nerdexam
CompTIA

SY0-501 · Question #304

A security administrator suspects that data on a server has been exhilarated as a result of un- authorized remote access. Which of the following would assist the administrator in con-firming the…

The correct answer is B. DLP alerts C. Log analysis. When investigating suspected data exfiltration via unauthorized remote access, administrators need tools that can detect data leaving the network and provide audit trails of activity. DLP alerts and log analysis are the best tools for confirming whether exfiltration occurred.

Submitted by helene.fr· Mar 4, 2026Security operations

Question

A security administrator suspects that data on a server has been exhilarated as a result of un- authorized remote access. Which of the following would assist the administrator in con-firming the suspicions? (Select TWO)

Options

  • ANetworking access control
  • BDLP alerts
  • CLog analysis
  • DFile integrity monitoring
  • EHost firewall rules

How the community answered

(23 responses)
  • A
    13% (3)
  • B
    78% (18)
  • D
    4% (1)
  • E
    4% (1)

Why each option

When investigating suspected data exfiltration via unauthorized remote access, administrators need tools that can detect data leaving the network and provide audit trails of activity. DLP alerts and log analysis are the best tools for confirming whether exfiltration occurred.

ANetworking access control

Network Access Control (NAC) enforces access policies to prevent unauthorized devices from connecting to the network but does not provide forensic evidence or alerts to confirm whether data exfiltration has already occurred.

BDLP alertsCorrect

Data Loss Prevention (DLP) solutions monitor and alert on sensitive data transfers, providing direct evidence of data exfiltration by identifying unauthorized outbound data flows, destinations, and the type of data transmitted - directly confirming whether data left the environment.

CLog analysisCorrect

Log analysis of server logs, authentication logs, and network logs provides a chronological audit trail of remote access sessions, user activity, commands executed, and data transfers, allowing the administrator to reconstruct the timeline and confirm unauthorized access and exfiltration.

DFile integrity monitoring

File Integrity Monitoring (FIM) detects unauthorized changes or modifications to files on a host, which could indicate tampering, but does not provide evidence that data was transmitted externally or confirm exfiltration.

EHost firewall rules

Host firewall rules define what traffic is allowed or blocked on a system but are a preventive control, not a detective one - reviewing rules alone does not confirm whether data was exfiltrated or provide evidence of unauthorized remote access activity.

Concept tested: Detecting and confirming data exfiltration via log analysis and DLP

Source: https://learn.microsoft.com/en-us/azure/sentinel/detect-threats-built-in

Topics

#DLP#log analysis#data exfiltration#incident investigation

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice