SY0-701 Security Operations Practice Question
An organization's file server contains sensitive HR data. The security team discovers that permissions on a confidential folder have been altered. Which of the following security controls would MOST likely help determine the account responsible for this change?
⚠ Common exam trap
A common mix-up: candidates confuse a preventive control like MAC or HIPS with a detective control like audit logging, failing to recognize that only audit logs provide the specific account attribution needed for this scenario.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Audit logging
Audit logging is the correct answer because it records detailed information about who made changes to files and folders, including the account name, timestamp, and the specific permission alteration. By reviewing audit logs, the security team can trace the unauthorized permission change back to the responsible user account. This is a detective control that directly supports accountability and forensic investigation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Data loss prevention (DLP) system
Why it's wrong here
A data loss prevention (DLP) system classifies and monitors data to enforce policies against unauthorized transfers or exfiltration, typically scanning network traffic, email, or endpoints. While it may generate alerts when sensitive HR data leaves the network, it does not track administrative actions like permission modifications on a file server, nor does it maintain a chronological record of user-driven changes to access control lists. DLP operates on data content and flow, not on the identity or history of configuration changes within the file system.
When this WOULD be correct
A question asking which control would prevent sensitive HR data from being emailed outside the organization would make DLP the correct answer.
- ✗
Mandatory access control (MAC)
Why it's wrong here
MAC is a security model that uses system-wide policies to control access to resources, typically based on labels. While it defines who can access what, it does not log or track the history of permission changes.
When this WOULD be correct
A question asking which control would prevent unauthorized users from modifying permissions on classified data, where the system enforces access based on security labels and user clearances, making MAC the correct answer.
- ✓
Audit logging
Why this is correct
Audit logging records user actions such as file access, modification, and permission changes. It provides a detailed trail that can be reviewed to identify the account responsible for altering permissions and the exact time of the change.
- ✗
Host-based intrusion prevention system (HIPS)
Why it's wrong here
A host-based intrusion prevention system (HIPS) inspects system calls, process behavior, and network activity to detect and block malicious behavior, such as buffer overflows or privilege escalation. It may generate security event logs for attack attempts, but it is not designed to log routine file-server administration, including changes to permissions or ownership, because those are legitimate management operations. Its focus is real-time threat prevention, not post-hoc accountability for authorized administrative changes.
When this WOULD be correct
An organization wants to detect and block unauthorized attempts to modify system files or registry keys on a critical server. Which security control would most likely prevent exploitation of a zero-day vulnerability targeting that host?
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SY0-701 exam frequently reuses these exact scenarios with slightly different constraints.
✓Audit loggingCorrect answer▾
Why this is correct
Audit logging records user actions such as file access, modification, and permission changes. It provides a detailed trail that can be reviewed to identify the account responsible for altering permissions and the exact time of the change.
✗Data loss prevention (DLP) systemWrong answer — click to see why▾
Why this is wrong here
A DLP system monitors and prevents unauthorized data transfers, but it does not track or log permission changes on file servers.
★ When this WOULD be the correct answer
A question asking which control would prevent sensitive HR data from being emailed outside the organization would make DLP the correct answer.
Why candidates choose this
Candidates may confuse DLP's data monitoring capabilities with the ability to track changes to permissions, or they may think DLP logs all file-related activities.
✗Mandatory access control (MAC)Wrong answer — click to see why▾
Why this is wrong here
Mandatory access control (MAC) is a policy model that enforces access based on labels and clearances, not a mechanism for auditing who changed permissions. It does not provide logs or accountability for changes.
★ When this WOULD be the correct answer
A question asking which control would prevent unauthorized users from modifying permissions on classified data, where the system enforces access based on security labels and user clearances, making MAC the correct answer.
Why candidates choose this
Candidates may confuse MAC with auditing because both involve access control, but MAC focuses on preventing changes via policy enforcement, not detecting who made a change.
✗Host-based intrusion prevention system (HIPS)Wrong answer — click to see why▾
Why this is wrong here
A host-based intrusion prevention system (HIPS) monitors and blocks malicious activities on a single host, but it does not log or track permission changes to files or folders. It is not designed to provide an audit trail of who altered file permissions.
★ When this WOULD be the correct answer
An organization wants to detect and block unauthorized attempts to modify system files or registry keys on a critical server. Which security control would most likely prevent exploitation of a zero-day vulnerability targeting that host?
Why candidates choose this
Candidates may confuse HIPS with host-based intrusion detection systems (HIDS) that can monitor file integrity, or they may think HIPS can log all host activities, including permission changes, due to its broad security scope.
Analysis generated from the official SY0-701blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Wireless Security Protocols
Key term
Audit
An audit is a systematic, independent review of IT systems, processes, and controls to verify compliance with policies, standards, and regulations.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.