SY0-701 Security Operations Practice Question
A security engineer is configuring a new endpoint detection and response (EDR) solution. The organization wants to detect when a user opens a malicious PDF that exploits a vulnerability in Adobe Reader to execute a shell. Which EDR capability should the engineer ensure is enabled to detect this activity?
⚠ Common exam trap
The trap here is focusing on file-based or network-based detections, but the exploitation may be fileless and the shell may not immediately communicate over the network.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Child process monitoring and process lineage tracking to detect Adobe Reader spawning a command shell.
Detecting a PDF exploiting Adobe Reader to spawn a shell requires monitoring process creation events and analyzing parent-child relationships. EDR solutions with child process monitoring can alert when a document reader spawns a command interpreter, which is highly suspicious. This detection works even if the shell is a legitimate binary, because the behavior is anomalous.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Network traffic analysis to detect command-and-control (C2) communication from the endpoint.
Why it's wrong here
Network traffic analysis can detect C2 after the shell is established, but it may not detect the initial exploitation. The shell might be used for local actions before any network communication, or the C2 could be encrypted. This capability is reactive and may miss the initial execution, so it is not the primary detection method for the described activity.
- ✗
File integrity monitoring (FIM) on the Adobe Reader installation directory to detect unauthorized changes.
Why it's wrong here
FIM detects changes to files, such as modifications to Adobe Reader's executables or DLLs. However, the exploitation may not modify files on disk; it could be a memory corruption exploit that executes a shell without writing to disk. FIM would not detect the process creation event, so it is not the right capability for this detection.
- ✓
Child process monitoring and process lineage tracking to detect Adobe Reader spawning a command shell.
Why this is correct
Child process monitoring tracks process creation events and can alert when a process like Adobe Reader (AcroRd32.exe) spawns a command shell (cmd.exe or powershell.exe). This is a classic indicator of exploitation. Process lineage provides context, showing the parent-child relationship, which is essential for detecting this behavior even if the shell is not malicious by itself.
- ✗
Script block logging and AMSI integration to capture PowerShell execution.
Why it's wrong here
Script block logging and AMSI are useful for detecting PowerShell-based attacks, but the scenario describes a PDF exploiting Adobe Reader to execute a shell, which may not involve PowerShell. The shell could be cmd.exe or another process. This capability would not detect the initial exploitation unless the shell then runs PowerShell, which is not specified.
Go deeper
Related to this question
Learn chapter
Incident Response Process
Key term
Vulnerability
A vulnerability is a weakness in a system, network, or software that could be exploited by a threat to cause harm or unauthorized access.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
Courseiva writes every SY0-701 question from scratch — 1,030 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.