SY0-701 Security Operations Practice Question
After a workstation hardening baseline is updated, the security team wants to confirm that finance laptops actually match the new settings. Which control is the best way to verify this?
⚠ Common exam trap
Candidates often confuse change management approval (Option C) with actual technical verification, overlooking the need for a direct compliance check to confirm implementation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Run a configuration compliance scan against the updated baseline
A configuration compliance scan compares the current settings of the finance laptops against the updated hardening baseline. This automated process checks specific registry keys, file permissions, service states, and security policy settings (e.g., via SCAP or CIS benchmarks) to verify alignment. It provides objective, measurable evidence of compliance, unlike subjective user feedback or assumptions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Run a configuration compliance scan against the updated baseline
Why this is correct
A configuration compliance scan is the definitive verification method because it programmatically compares each endpoint's actual registry keys, service states, group policy settings, and installed software against the approved hardening baseline. This identifies even minor deviations such as a disabled firewall rule or an outdated patch level, giving security teams concrete evidence of compliance or drift. Unlike subjective assessments, a scan produces reproducible, auditable results that directly reflect whether the updated baseline was successfully deployed.
- ✗
Ask users whether they think their laptops are secure
Why it's wrong here
Asking users for their opinions is not a valid technical control because users typically lack visibility into low-level security settings like audit policy, cipher suites, or user rights assignments. A laptop may appear to work normally while failing dozens of baseline checks, and users cannot detect misconfigurations that do not visibly affect functionality. This approach introduces confirmation bias and provides no measurable, verifiable data for the security team.
- ✗
Assume the baseline was applied because the change ticket was approved
Why it's wrong here
Change ticket approval signifies that the request was authorized, not that the technical implementation succeeded on every target device. Deployment can fail silently due to GPO replication delays, incompatible drivers, closed ports, or agent errors, leaving systems in a non-compliant state. Trusting the approval alone bypasses the principle of verification and would allow misconfigurations to remain undetected, potentially exposing the organization to risk.
- ✗
Delete the old baseline so there is only one policy to reference
Why it's wrong here
Deleting the old baseline does nothing to verify the current state of the endpoints; it only destroys historical reference data. Without the prior baseline, you lose the ability to compare before-and-after configurations, making it harder to identify unintended changes or revert problematic settings. This action also weakens change management and audit trails, violating the need to maintain documented security standards for compliance reviews.
Go deeper
Related to this question
Learn chapter
Incident Response Process
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
Key term
Compliance scan
A compliance scan is an automated security assessment that checks systems, networks, and applications against a defined set of regulatory or organizational standards to verify adherence to required policies.
About these practice questions
Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.