Courseiva
Security ArchitectureeasyMultiple ChoiceObjective-mapped

SY0-701 Security Architecture Practice Question

A security team wants to know whether a workstation has drifted away from the approved hardened configuration after several months of changes. What should they use to compare the current state against the approved setup?

⚠ Common exam trap

Many exam-takers confuse a configuration baseline with a backup or recovery tool, thinking a file compression tool could somehow 'compare' states, when in fact baselines are specifically designed for compliance drift analysis.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

A configuration baseline

A configuration baseline is the approved hardened state of a system, typically captured as a snapshot of settings, registry keys, file permissions, and installed software. By comparing the current workstation state against this baseline using tools like Microsoft Security Compliance Toolkit or CIS-CAT, the team can detect drift—unauthorized changes that deviate from the secure configuration. This is the standard method for maintaining compliance and security posture over time.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • A file compression tool

    Why it's wrong here

    Compression utilities like ZIP or gzip reduce file size for storage or transfer, but they do not analyze or compare configuration states. Drift detection requires a reference baseline of expected settings and a mechanism to measure deviations, such as checking hash values or auditing policy settings. A compression tool may package baseline files, but it lacks the logic to interpret or compare them against live system states. Therefore, it cannot determine if a workstation has drifted from its approved configuration.

  • A configuration baseline

    Why this is correct

    A configuration baseline is a documented set of security and operational settings that define the approved, secure state for a system, such as CIS benchmarks or organizational hardening guidelines. Drift detection works by regularly collecting the current configuration (e.g., via agent or assessment tool) and comparing it to this baseline, flagging any differences as non-compliance. This baseline serves as the authoritative reference point, enabling automated or manual identification of unauthorized or unintended changes. Hence, a configuration baseline is the correct tool for detecting drift.

  • A password vault

    Why it's wrong here

    A password vault securely stores and manages credentials, typically encrypting them and enforcing access policies. However, drift detection involves comparing a system's current configuration state against a known-good baseline (e.g., registry keys, file hashes, security policy settings). A vault contains secrets, not system configuration snapshots, so it cannot identify unauthorized changes like a disabled firewall rule or altered Group Policy object. Thus, it is the wrong tool for drift assessment.

  • A network cable tester

    Why it's wrong here

    A network cable tester verifies physical layer characteristics like wiring continuity, pinouts, and signal integrity, which are relevant for connectivity issues. Drift refers to configuration drift, a logical state where a system's settings deviate from a chosen standard over time (e.g., due to manual updates or software installations). A cable tester cannot inspect operating system settings, installed applications, or security policies, so it is completely unrelated to configuration drift detection. Therefore, it is an incorrect choice.

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.