nerdexam
CompTIACompTIA

SY0-501 · Question #434

SY0-501 Question #434: Real Exam Question with Answer & Explanation

Sign in or unlock SY0-501 to reveal the answer and full explanation for question #434. The question stem and answer options stay visible for context.

Submitted by daniela_cl· Mar 4, 2026

Question

A security analyst is acquiring data from a potential network incident. Which of the following evidence is the analyst MOST likely to obtain to determine the incident?

Options

  • AVolatile memory capture
  • BTraffic and logs
  • CScreenshots
  • DSystem image capture

Unlock SY0-501 to see the answer

You've previewed enough free SY0-501 questions. Unlock SY0-501 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Full SY0-501 PracticeBrowse All SY0-501 Questions