Courseiva
Security OperationsmediumMultiple ChoiceObjective-mapped

SY0-701 Security Operations Practice Question

A SOC analyst receives an alert that a domain admin account authenticated to a file server at 02:14 from a jump host that is normally used only by the infrastructure team. The Windows logs also show a scheduled task launching a backup script at the same time, and the backup team says the task was created during yesterday's change window. What is the best next step to determine whether this is a false positive?

⚠ Common exam trap

Candidates often assume any after-hours admin login is malicious, but the scheduled task created during a change window provides a legitimate explanation that must be verified through correlation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Correlate the authentication event with the change ticket and the scheduled task details.

The alert involves a domain admin authentication from a jump host at an unusual time, but the scheduled task was created during a change window. Correlating the authentication event with the change ticket and the scheduled task details allows the SOC analyst to verify if the activity was authorized, preventing unnecessary incident response. This step aligns with the incident response process of validating alerts before taking action.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Disable the domain admin account immediately and wait for the backup team to respond.

    Why it's wrong here

    Disabling the domain admin account without validation is a destructive, high-impact action that treats an unconfirmed alert as a confirmed breach. If the login corresponds to an approved maintenance task, this response would interrupt legitimate backup operations and potentially violate change-management policies. Moreover, it poisons the investigative process by eliminating the account's ability to provide additional evidence of compromise. The correct sequence is to validate the event against the change ticket and scheduled task before taking any account-level action.

  • Correlate the authentication event with the change ticket and the scheduled task details.

    Why this is correct

    Correlating the authentication event with the change ticket and scheduled task details is the foundational verification step. Because scheduled tasks run under specific security principals, a match between the login time, source, and the task's execution window provides strong evidence that the activity was expected and legitimate. This approach reduces false positives while preserving any potentially malicious evidence for later analysis. It distinguishes an authorized administrative workflow from an attacker's authentication attempt, enabling an informed risk-based decision.

  • Escalate the alert as confirmed compromise because the login occurred after hours.

    Why it's wrong here

    Escalating as a confirmed compromise solely because the login occurred after hours is an over-reaction based on a single heuristic. Off-hours administrative work is often scheduled during change windows to minimize business impact, so time of day alone lacks the contextual evidence needed for a confirmed declaration. A validated compromise requires corroborating indicators like impossible travel, unusual source addresses, or deviation from known account behavior. Escalating prematurely exhausts incident-response resources and may trigger recovery procedures that are themselves disruptive.

  • Delete the scheduled task so it cannot be used again.

    Why it's wrong here

    Deleting the scheduled task is a premature and destructive action that removes valuable forensic context before the alert is validated. The task may be a legitimate backup job, and its deletion could interrupt business continuity and obscure the exact command executed by the administrator. Even if the task were malicious, deleting it leaves the underlying malware or persistence mechanism untouched and destroys evidence needed for attribution. The analyst should first inspect the task's arguments, owner, and run history to determine whether it aligns with approved change records.

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.