SY0-701 Security Operations Practice Question
A security analyst is investigating a potential data exfiltration incident. The analyst has collected network flow data, proxy logs, and endpoint logs. Which two data sources should the analyst correlate to identify the exfiltration channel and the compromised host? (Choose two.)
⚠ Common exam trap
The trap here is focusing on perimeter logs like firewall or DNS, but those may not provide the process-level context needed to definitively identify the compromised host and channel.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Proxy logs to identify HTTP/HTTPS connections to external destinations.
Correlating proxy logs with endpoint logs allows the analyst to link outbound web connections to specific processes on specific hosts. Proxy logs show the destination and volume of data, while endpoint logs show which process initiated the connection. Together, they can identify the exfiltration channel (e.g., HTTP POST to a foreign server) and the compromised host (by hostname or IP).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Proxy logs to identify HTTP/HTTPS connections to external destinations.
Why this is correct
Proxy logs record outbound web requests, including the source host, destination URL, and amount of data transferred. By analyzing these logs, the analyst can identify unusual connections to external sites, such as large uploads or connections to known malicious domains, which may indicate exfiltration over HTTP/HTTPS. This helps identify both the channel and the compromised host.
- ✓
Endpoint logs to identify processes that initiated network connections.
Why this is correct
Endpoint logs, such as EDR or Sysmon logs, provide process-level detail, including which process initiated a network connection and to which remote IP or domain. Correlating this with proxy logs can pinpoint the exact process responsible for the exfiltration, confirming the compromised host and the method used. This is essential for a thorough investigation.
- ✗
Firewall logs to identify blocked inbound connection attempts.
Why it's wrong here
Firewall logs showing blocked inbound connections are not directly relevant to data exfiltration, which involves outbound data transfers. While they might indicate scanning or attack attempts, they do not help identify the exfiltration channel or the compromised host in this scenario. The focus should be on outbound traffic.
- ✗
DNS logs to identify domain name resolutions from internal hosts.
Why it's wrong here
DNS logs can reveal domains queried by internal hosts, which might indicate connections to malicious domains. However, they do not show the actual data transfer or the process responsible. While they can be useful for identifying potential C2 or exfiltration domains, they are less direct than proxy and endpoint logs for identifying the channel and host in this context.
- ✗
DHCP logs to identify IP address assignments to hosts.
Why it's wrong here
DHCP logs map IP addresses to MAC addresses and hostnames over time. While useful for identifying which host had a particular IP at a given time, they do not provide information about the exfiltration channel or the data transferred. They are supplementary but not one of the two primary sources to correlate for this purpose.
Go deeper
Related to this question
Learn chapter
Post-Incident Review and Lessons Learned
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
Key term
Proxy
A proxy is an intermediary server that sits between a client and a destination server, forwarding requests and responses while providing security, privacy, and control.
About these practice questions
One of 1,030 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.