Security Operations

This domain carries 28% of the SY0-701 exam. Practise it with original questions that explain every answer option.

Practise this domain free

Certification
SY0-701
Exam weight
28%
Subdomains
9
Objectives
47

What this domain covers

Given a Scenario, Apply Common Security Techniques to Computing Resources5 topics
Explain the Security Implications of Proper Hardware, Software, and Data Asset Management5 topics
Explain Various Activities Associated with Vulnerability Management6 topics
Explain Security Alerting and Monitoring Concepts and Tools5 topics
Given a Scenario, Modify Enterprise Capabilities to Enhance Security5 topics
Given a Scenario, Implement and Maintain Identity and Access Management5 topics
Explain the Importance of Automation and Orchestration Related to Secure Operations5 topics

Example question from this domain

An AdTech company’s SOAR platform triggered alerts for anomalous, low-and-slow exfiltration of PII such as device IDs and IP addresses. Initial playbooks contained some indicators, but the full scope and persistence are still unclear. Which approach best uses SOAR to investigate the threat and improve future PII protection, especially to uncover unknown TTPs?

  • Integrate new external threat intelligence feeds into SOAR to automatically block all connections matching newly published IoCs.
  • Use SOAR to orchestrate threat-hunting queries across bid stream logs, CDN access logs, and consent management audit trails, then automate newly discovered internal IoCs into response playbooks.
  • Manually isolate suspected servers and use standalone forensic tools, bypassing SOAR to prevent further leakage.
  • Use SOAR only to generate GDPR and CCPA compliance reports, prioritizing legal obligations over active investigation.

Integrate new external threat intelligence feeds into SOAR to automatically block all connections matching newly published IoCs. — External threat feeds are useful, but a sophisticated low-and-slow attack may use environment-specific methods not yet in those feeds. Blocking known IoCs is reactive and can miss the root cause, persistence, and unknown TTPs needed to fully address the breach.

Use SOAR to orchestrate threat-hunting queries across bid stream logs, CDN access logs, and consent management audit trails, then automate newly discovered internal IoCs into response playbooks. — SOAR can coordinate searches across multiple high-volume data sources so hunters can look for subtle, previously unknown TTPs tied to PII exfiltration. Newly found internal IoCs can then be added to playbooks, improving future detection and response in a continuous feedback loop.

Manually isolate suspected servers and use standalone forensic tools, bypassing SOAR to prevent further leakage. — Manual investigation is important, but skipping SOAR wastes its ability to aggregate data, automate collection, and coordinate response actions. In a high-throughput AdTech environment, that makes containment slower and reduces the chance of building reusable detections for future incidents.

Use SOAR only to generate GDPR and CCPA compliance reports, prioritizing legal obligations over active investigation. — Compliance reporting matters, but it should follow containment and investigation. Using SOAR only for reports ignores the immediate need to identify scope, stop exfiltration, and eradicate the attacker, which is essential before accurate regulatory reporting can be completed.

Continue with SY0-701

Domain names and weightings follow the vendor's published exam guide. ExamNova questions are written in-house and are not exam dumps.