Courseiva
Security Operations →mediumMultiple Select

SY0-701 Security Operations Practice Question

A security analyst is investigating a potential data exfiltration incident. The analyst has collected network flow data, proxy logs, and endpoint logs. Which two data sources should the analyst correlate to identify the exfiltration channel and the compromised host? (Choose two.)

⚠ Common exam trap

The trap here is focusing on perimeter logs like firewall or DNS, but those may not provide the process-level context needed to definitively identify the compromised host and channel.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Proxy logs to identify HTTP/HTTPS connections to external destinations.

Correlating proxy logs with endpoint logs allows the analyst to link outbound web connections to specific processes on specific hosts. Proxy logs show the destination and volume of data, while endpoint logs show which process initiated the connection. Together, they can identify the exfiltration channel (e.g., HTTP POST to a foreign server) and the compromised host (by hostname or IP).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Proxy logs to identify HTTP/HTTPS connections to external destinations.

    Why this is correct

    Proxy logs record outbound web requests, including the source host, destination URL, and amount of data transferred. By analyzing these logs, the analyst can identify unusual connections to external sites, such as large uploads or connections to known malicious domains, which may indicate exfiltration over HTTP/HTTPS. This helps identify both the channel and the compromised host.

  • ✓

    Endpoint logs to identify processes that initiated network connections.

    Why this is correct

    Endpoint logs, such as EDR or Sysmon logs, provide process-level detail, including which process initiated a network connection and to which remote IP or domain. Correlating this with proxy logs can pinpoint the exact process responsible for the exfiltration, confirming the compromised host and the method used. This is essential for a thorough investigation.

  • ✗

    Firewall logs to identify blocked inbound connection attempts.

    Why it's wrong here

    Firewall logs showing blocked inbound connections are not directly relevant to data exfiltration, which involves outbound data transfers. While they might indicate scanning or attack attempts, they do not help identify the exfiltration channel or the compromised host in this scenario. The focus should be on outbound traffic.

  • ✗

    DNS logs to identify domain name resolutions from internal hosts.

    Why it's wrong here

    DNS logs can reveal domains queried by internal hosts, which might indicate connections to malicious domains. However, they do not show the actual data transfer or the process responsible. While they can be useful for identifying potential C2 or exfiltration domains, they are less direct than proxy and endpoint logs for identifying the channel and host in this context.

  • ✗

    DHCP logs to identify IP address assignments to hosts.

    Why it's wrong here

    DHCP logs map IP addresses to MAC addresses and hostnames over time. While useful for identifying which host had a particular IP at a given time, they do not provide information about the exfiltration channel or the data transferred. They are supplementary but not one of the two primary sources to correlate for this purpose.

About these practice questions

One of 1,030 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.