Courseiva
Security OperationshardMatchingObjective-mapped

SY0-701 Security Operations Practice Question

Match each SOC alert artifact to the most useful investigation pivot. Each pivot should help determine whether the alert is a true incident, a false positive, or part of a broader campaign.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Check whether the pattern matches password spraying across accounts rather than a brute-force attempt on one user.

Pivot to parent-child process trees and script-block telemetry on the endpoint.

Compare the query pattern and periodicity for possible DNS tunneling or beaconing.

Correlate with scheduled tasks, recent file creation, and account activity for staging or exfiltration.

Review token/session logs and conditional-access telemetry to see whether a hijacked session or relay attack occurred.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

IP address: Perform reputation check against known threat feeds.

Each artifact is matched to a pivot that directly aids in verifying the alert's validity, whether by checking reputation, correlating with threat intelligence, or comparing against normal behavior.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • IP address: Perform reputation check against known threat feeds.

    Why this is correct

    Reputation checks against threat feeds are the most efficient way to triage an IP address because these feeds aggregate historical and real-time data from multiple sources, scoring IPs based on observed malicious activity such as command-and-control communication, port scanning, or phishing campaigns. A high reputation score immediately indicates whether the IP is a known threat actor, enabling rapid prioritization of the alert.

  • File hash: Query threat intelligence databases for known malware signatures.

    Why this is correct

    Querying threat intelligence databases with a file hash is the most direct investigative method because hashes act as unique digital fingerprints; known malware samples have pre-computed hashes stored in repositories like VirusTotal, MISP, or sandbox analysis reports. This static analysis quickly identifies the malware family and associated behavior without needing to execute the file.

  • IP address: Conduct WHOIS lookup to verify registration details.

    Why it's wrong here

    WHOIS lookup via a registrar is designed for domain names, not IP addresses; IP allocations are tracked by regional internet registries (e.g., ARIN, RIPE), and even then, WHOIS yields only registration and contact details, not threat context. While it may provide ownership information for attribution, it cannot indicate whether the IP is actively malicious, making it far less useful than a reputation check.

  • File hash: Perform memory analysis on the endpoint.

    Why it's wrong here

    Memory analysis examines volatile runtime artifacts such as running processes, open network connections, and loaded drivers—not static artifacts like file hashes. To investigate a file hash, you would need to retrieve the file and perform static analysis or detonate it in a sandbox; memory analysis is only relevant if the file's process is actively resident, but it does not directly profile the hash itself.

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.