nerdexam
CompTIA

SY0-701 · Question #1080

Multiple users report that they cannot access a certain application after a recent security update. Which of the following should the security team check first to help find the root cause?

The correct answer is B. IPS/IDS logs. After a security update, an IPS or IDS may begin blocking or resetting connections it now identifies as malicious or noncompliant, so reviewing its logs first helps quickly determine whether the update is preventing access to the application.

Submitted by jordan8· Mar 6, 2026Security Operations

Question

Multiple users report that they cannot access a certain application after a recent security update. Which of the following should the security team check first to help find the root cause?

Options

  • AProxy logs
  • BIPS/IDS logs
  • CSIEM logs
  • DDNS logs

How the community answered

(16 responses)
  • A
    13% (2)
  • B
    56% (9)
  • C
    25% (4)
  • D
    6% (1)

Explanation

After a security update, an IPS or IDS may begin blocking or resetting connections it now identifies as malicious or noncompliant, so reviewing its logs first helps quickly determine whether the update is preventing access to the application.

Community Discussion

No community discussion yet for this question.

Full SY0-701 Practice