exam questions

Exam SY0-701 All Questions

View all questions & answers for the SY0-701 exam

Exam SY0-701 topic 1 question 70 discussion

Actual exam question from CompTIA's SY0-701
Question #: 70
Topic #: 1
[All SY0-701 Questions]

A security operations center determines that the malicious activity detected on a server is normal. Which of the following activities describes the act of ignoring detected activity in the future?

  • A. Tuning
  • B. Aggregating
  • C. Quarantining
  • D. Archiving
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
jovines
Highly Voted 11 months, 2 weeks ago
The act of ignoring detected activity in the future is described as A. Tuning. Tuning refers to the process of adjusting the configuration of a system, in this case, the security operations center’s detection systems, to reduce or eliminate the number of false positives. In this context, if the so-called “malicious activity” is determined to be normal and is expected to recur, the system can be tuned to ignore this activity in the future, preventing unnecessary alerts. Please note that while the other options (B. Aggregating, C. Quarantining, D. Archiving) are activities related to managing and responding to security events, they do not specifically apply to the scenario of ignoring detected activity in the future.
upvoted 22 times
...
Mehsotopes
Highly Voted 11 months, 2 weeks ago
Selected Answer: A
Tuning is setting a monitoring system to have higher, or lower threat detection standards.
upvoted 10 times
...
MarysSon
Most Recent 4 weeks ago
Selected Answer: A
But the real answer is E - None of the above. Tuning is an act of adjusting and optimizing a set of configurations to reduce risk, improve security, and improve performance. That is hardly ignoring. A system might ignore a symptom. but the security administrator does not. This question should be rephrased.
upvoted 1 times
...
NONS3c
7 months, 2 weeks ago
Selected Answer: A
" malicious activity detected on a server is normal" this is a key word it mean that we have fail positive so tuning working on fixing and improve performance or efficiency.
upvoted 3 times
...
dbrowndiver
8 months, 3 weeks ago
Selected Answer: A
Tuning is the process of configuring security tools and systems to reduce false positives and ensure that alerts are meaningful. It involves adjusting the parameters and rules of the detection systems to ignore certain activities that have been determined to be normal or non-threatening.Tuning is also the appropriate action to take when a particular activity has been analyzed and deemed safe, allowing the security system to ignore similar future alerts and reducing unnecessary alert fatigue.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago