Courseiva
Security OperationsmediumMatchingObjective-mapped

SY0-701 Security Operations Practice Question

Match each security monitoring artifact from the SOC alert queue to the best investigation focus.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Investigate possible script-based malware execution launched through a document

Check for suspicious domain lookups that may indicate command-and-control activity

Look for beaconing behavior from a potentially compromised endpoint

Assess for stolen credentials or credential-stuffing activity

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Phishing: Investigate email headers and links

Each alert type suggests a specific investigation focus: phishing requires email analysis; malware needs file/behavior analysis; brute force focuses on auth logs; data exfiltration looks at outbound traffic; privileged misuse examines user activity; ransomware involves encryption events.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Phishing: Investigate email headers and links

    Why this is correct

    Phishing investigations should start with the email message itself—analyzing full SMTP headers for SPF, DKIM, and DMARC validation failures, examining embedded URLs against reputation services, and sandboxing attachments to observe malicious behavior. Header anomalies like mismatched Reply-To or spoofed sender domains are strong signals, and link analysis often reveals credential-harvesting lures. This is the correct primary artifact focus for phishing, distinctly different from host-based malware analysis.

  • Malware: Analyze file hashes and process behavior

    Why this is correct

    Malware analysis centers on identifying the malicious file and its runtime behavior. Investigators compute file hashes (MD5, SHA-256) and query them against known-bad threat intelligence to classify the sample, then observe process execution—looking for abnormal child processes, injected threads, registry persistence keys, or suspicious network connections from the infected host. These host-centric artifacts confirm active infection and are separate from email-content artifacts used in phishing investigations.

  • Brute force: Audit user activity logs for unusual administrative actions

    Why it's wrong here

    Auditing user activity logs for unusual administrative actions would detect privileged misuse, not brute force. Brute-force attacks manifest as a high volume of failed authentication attempts, often across numerous accounts or from a single source IP, with rapid-fire login patterns and account lockouts. Investigators should review authentication and access logs for repeated login failures, not administrative action logs—making this pairing incorrect because the artifact type does not match the attack's core behavior.

  • Data exfiltration: Check for file encryption events and ransom notes

    Why it's wrong here

    Checking for file encryption events and ransom notes is the artifact signature of ransomware, not data exfiltration. Exfiltration is a network-focused investigation involving large outbound transactions, DNS tunneling, or unexpected uploads to cloud storage, which would be visible in netflow or proxy logs. While ransomware may sometimes include data theft, the defining artifacts of exfiltration alone are outbound volume anomalies, making this option's mapping wrong.

  • Privileged misuse: Monitor outbound traffic volume to unusual destinations

    Why it's wrong here

    Monitoring outbound traffic volume to unusual destinations is the hallmark of data exfiltration, where sensitive data leaves the network. Privileged misuse, by contrast, involves legitimate but inappropriate activity by an account with elevated permissions—such as an admin accessing sensitive records or creating unauthorized accounts. This requires auditing user activity logs for behavior anomalies, not baselining egress network traffic, so this option incorrectly swaps two distinct detection categories.

  • Ransomware: Review authentication logs for repeated failures

    Why it's wrong here

    Reviewing authentication logs for repeated failures targets brute-force credential attacks, not ransomware. Ransomware artifacts include mass file encryption events, unusual file renames, and ransom notes, often accompanied by lateral movement or C2 network activity. An investigation focused on authentication failures during a ransomware incident would miss the actual encryption timeline and potentially fail to contain the true threat, showing why this artifact-to-threat pairing is wrong.

About these practice questions

One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SY0-701

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Match each SOC alert artifact to the most useful investigation pivot. Each pivot should help determine whether the alert is a true incident, a false positive, or part of a broader campaign.

hard
  • A.IP address: Perform reputation check against known threat feeds.
  • B.File hash: Query threat intelligence databases for known malware signatures.
  • C.IP address: Conduct WHOIS lookup to verify registration details.
  • D.File hash: Perform memory analysis on the endpoint.

Why A: Each artifact is matched to a pivot that directly aids in verifying the alert's validity, whether by checking reputation, correlating with threat intelligence, or comparing against normal behavior.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.