SY0-701 Security Operations Practice Question
Exhibit
10:00:02 patch-srv-12 service 'AcmePatchAgent' started by NT AUTHORITY\SYSTEM 10:00:05 patch-srv-12 DNS query: updates.acmecorp.com -> 198.51.100.44 10:00:05 patch-srv-12 outbound TLS connection to 198.51.100.44:443 10:00:07 SIEM rule 'possible beaconing every 15 minutes' triggered 10:15:03 patch-srv-12 DNS query: updates.acmecorp.com -> 198.51.100.44 10:15:03 patch-srv-12 outbound TLS connection to 198.51.100.44:443 10:15:04 EDR metadata: process hash matches approved vendor signature CMDB: Asset group = Patch Management Server; maintenance window = daily 10:00-10:30
Based on the exhibit, what is the most likely SOC conclusion and next action?
A scheduled alert fired on a server that repeatedly connects to a vendor update site at fixed intervals. The security team wants to know whether the alert represents a real threat or a harmless operational pattern.
⚠ Common exam trap
The trap here is that candidates see 'scheduled alert' and 'fixed intervals' and immediately think of C2 beaconing, but the key differentiator is the destination being a known vendor update site, which points to a false positive rather than a threat.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Classify the alert as a likely false positive, verify it against the maintenance record, and tune the rule.
The scheduled alert firing at fixed intervals to a known vendor update site strongly suggests a legitimate update or heartbeat mechanism, not malicious C2 traffic. Option B correctly directs the analyst to verify against maintenance records (confirming the pattern is expected) and then tune the rule to reduce future false positives, which is the standard SOC workflow for benign scheduled activity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Treat the activity as confirmed command-and-control traffic and isolate the server immediately.
Why it's wrong here
The exhibit shows a signed patch-management agent operating on its designated server, sending periodic updates to the vendor's official host; this is not an unrecognized process or destination. Confirmed C2 requires corroborating indicators such as anomalous process injection, unusual command-line arguments, or threat-intel matches, none of which appear. Isolating immediately could disrupt critical patch operations and is premature without validating the artifact's integrity.
- ✓
Classify the alert as a likely false positive, verify it against the maintenance record, and tune the rule.
Why this is correct
The logs show a signed, approved patch agent on a server explicitly assigned to patch management, connecting to the vendor update host on a predictable schedule. That pattern matches normal operations rather than covert beaconing. The best SOC action is to validate the asset and change context, document the finding, and tune the detection logic or allowlist the known-good behavior.
- ✗
Assume DNS poisoning is occurring and immediately flush the DNS cache on every endpoint.
Why it's wrong here
DNS poisoning would hinge on evidence that the host resolved the vendor domain to a rogue IP, yet the logs show a direct connection to the vendor's legitimate update host with no name-resolution mismatch. Neither the query pattern nor the response data indicates cache tampering, spoofed answers, or a DNS redirection attack. Flushing DNS on all endpoints is a broad containment step that would have no effect on a direct outbound connection already established, and it ignores the absence of any poisoning indicator.
- ✗
Open a credential theft incident and reset all administrator passwords across the environment.
Why it's wrong here
Credential theft incidents typically involve anomalies in authentication—such as unusual logon times, locations, or privileged token use—but the exhibit only reflects a machine account running a scheduled patch task with no login events or lateral movement. Resetting all administrator passwords is an invasive countermeasure that would likely break service accounts and password-manager dependencies, causing significant availability impact. Without evidence of credential misuse or unauthorized access from this host, such an action is unsupported by the available data.
Go deeper
Related to this question
Learn chapter
Wireless Security Protocols
Key term
Standard
A standard is an agreed-upon set of rules, guidelines, or specifications that ensure consistency, compatibility, and quality across IT products, services, and processes.
Key term
Threat
A threat is any potential danger that could harm a computer system, network, or data, whether from a malicious hacker, a natural disaster, or an accidental mistake.
About these practice questions
Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.