CompTIA Security+ SY0-701 Practice Question

A company has noticed unusual activity on their network and has started an investigation. As a security analyst, you are reviewing logs from various endpoints to identify the source of the activity. Which of the following log entries would likely indicate a security incident in progress?

  • Periodic security scanning by the in-house vulnerability management tool.

  • Repeated login failures from a single source, followed by a successful login to an administrative account.

  • A single successful login to a user account during working hours.

  • Scheduled system updates being applied outside of office hours.

CompTIA Security+ SY0-701
Security Operations
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot