CompTIACompTIA
SY0-501 · Question #434
SY0-501 Question #434: Real Exam Question with Answer & Explanation
Sign in or unlock SY0-501 to reveal the answer and full explanation for question #434. The question stem and answer options stay visible for context.
Submitted by daniela_cl· Mar 4, 2026
Question
A security analyst is acquiring data from a potential network incident. Which of the following evidence is the analyst MOST likely to obtain to determine the incident?
Options
- AVolatile memory capture
- BTraffic and logs
- CScreenshots
- DSystem image capture
Unlock SY0-501 to see the answer
You've previewed enough free SY0-501 questions. Unlock SY0-501 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.