SY0-701 Security Architecture Practice Question
A security team wants to know whether a workstation has drifted away from the approved hardened configuration after several months of changes. What should they use to compare the current state against the approved setup?
⚠ Common exam trap
Many exam-takers confuse a configuration baseline with a backup or recovery tool, thinking a file compression tool could somehow 'compare' states, when in fact baselines are specifically designed for compliance drift analysis.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A configuration baseline
A configuration baseline is the approved hardened state of a system, typically captured as a snapshot of settings, registry keys, file permissions, and installed software. By comparing the current workstation state against this baseline using tools like Microsoft Security Compliance Toolkit or CIS-CAT, the team can detect drift—unauthorized changes that deviate from the secure configuration. This is the standard method for maintaining compliance and security posture over time.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A file compression tool
Why it's wrong here
Compression utilities like ZIP or gzip reduce file size for storage or transfer, but they do not analyze or compare configuration states. Drift detection requires a reference baseline of expected settings and a mechanism to measure deviations, such as checking hash values or auditing policy settings. A compression tool may package baseline files, but it lacks the logic to interpret or compare them against live system states. Therefore, it cannot determine if a workstation has drifted from its approved configuration.
- ✓
A configuration baseline
Why this is correct
A configuration baseline is a documented set of security and operational settings that define the approved, secure state for a system, such as CIS benchmarks or organizational hardening guidelines. Drift detection works by regularly collecting the current configuration (e.g., via agent or assessment tool) and comparing it to this baseline, flagging any differences as non-compliance. This baseline serves as the authoritative reference point, enabling automated or manual identification of unauthorized or unintended changes. Hence, a configuration baseline is the correct tool for detecting drift.
- ✗
A password vault
Why it's wrong here
A password vault securely stores and manages credentials, typically encrypting them and enforcing access policies. However, drift detection involves comparing a system's current configuration state against a known-good baseline (e.g., registry keys, file hashes, security policy settings). A vault contains secrets, not system configuration snapshots, so it cannot identify unauthorized changes like a disabled firewall rule or altered Group Policy object. Thus, it is the wrong tool for drift assessment.
- ✗
A network cable tester
Why it's wrong here
A network cable tester verifies physical layer characteristics like wiring continuity, pinouts, and signal integrity, which are relevant for connectivity issues. Drift refers to configuration drift, a logical state where a system's settings deviate from a chosen standard over time (e.g., due to manual updates or software installations). A cable tester cannot inspect operating system settings, installed applications, or security policies, so it is completely unrelated to configuration drift detection. Therefore, it is an incorrect choice.
Go deeper
Related to this question
Learn chapter
Cloud Security Fundamentals
Key term
Security posture
An organization's overall cybersecurity strength, including policies, controls, and readiness to defend against and respond to threats.
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.