Courseiva
Threats, Vulnerabilities, and MitigationsmediumMultiple ChoiceObjective-mapped

SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question

SIEM alerts show one workstation making SMB connections to 30 internal hosts within 10 minutes, followed by remote service creation and repeated access attempts to admin shares. The workstation also begins authenticating with several privileged accounts. What is the most likely activity?

⚠ Common exam trap

Candidates often confuse lateral movement with a DDoS attack because of the many outbound connections, but the key differentiator is the use of admin shares and privileged account authentication, which are hallmarks of post-exploitation lateral movement, not volumetric attacks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Lateral movement after credential compromise or endpoint takeover.

The sequence of SMB connections to many internal hosts, followed by remote service creation and repeated access attempts to admin shares, combined with authentication using privileged accounts, is the classic pattern of lateral movement. This indicates the attacker has already compromised the workstation (endpoint takeover) or obtained valid credentials and is now using SMB and PsExec-like techniques to move laterally across the network, escalate privileges, and establish persistence.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • A distributed denial-of-service attack launched from a compromised internal host.

    Why it's wrong here

    A DDoS attack aims to overwhelm a target service with volumetric or protocol-based floods, typically generating massive traffic toward a single external or internal host. The observed behavior—SMB connections spreading to 30 distinct workstations, admin-share access, and remote service creation—indicates interactive, application-layer execution rather than bandwidth exhaustion. Additionally, DDoS operations rarely require authenticating with privileged accounts, whereas these alerts show repeated authentication attempts consistent with credential-based lateral movement.

  • DNS tunneling used to exfiltrate data through allowed name-resolution traffic.

    Why it's wrong here

    DNS tunneling covertly embeds data in DNS queries and responses, usually directed at a single attacker-controlled domain with a high volume of small, oddly formed name-resolution requests. The SIEM evidence here centers on SMB (port 445) connections to numerous internal IPs, attempts to access administrative shares, and the creation of remote services—none of which are implemented over DNS. Without corresponding anomalies in DNS logs, such as unusual TXT records or excessive NXDOMAIN replies, DNS tunneling is an implausible explanation for these specific network artifacts.

  • ARP spoofing to redirect local traffic at the network layer.

    Why it's wrong here

    ARP spoofing is a Layer 2 technique that manipulates the ARP cache of hosts on the same broadcast domain to intercept or redirect local traffic, typically enabling man-in-the-middle attacks. It is inherently restricted to a single subnet and does not facilitate direct SMB connections to 30 separate hosts across the network, nor does it involve remote service creation or privileged account authentication. The SMB admin-share behavior operates at the application layer using Windows filesharing protocols, which ARP manipulation alone could not generate or explain.

  • Lateral movement after credential compromise or endpoint takeover.

    Why this is correct

    The workstation is behaving like an attacker foothold that is probing internal systems, using administrative shares, and attempting remote service creation. Those are strong signs of lateral movement after credentials or the device itself have been compromised. The privileged-account authentication attempts also suggest the attacker is trying to expand access and reach higher-value systems inside the environment.

About these practice questions

One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.