nerdexam
CompTIA

SY0-701 · Question #1084

A security analyst investigates abnormal outbound traffic from a corporate endpoint. The traffic is encrypted and uses non-standard ports. Which of the following data sources should the analyst use fi

Sign in or unlock SY0-701 to reveal the answer and full explanation for question #1084. The question stem and answer options stay visible for context.

Submitted by ngozi_ng· Mar 6, 2026Security Operations

Question

A security analyst investigates abnormal outbound traffic from a corporate endpoint. The traffic is encrypted and uses non-standard ports. Which of the following data sources should the analyst use first to confirm whether this traffic is malicious?

Options

  • AApplication logs
  • BVulnerability scans
  • CEndpoint logs
  • DPacket captures

Unlock SY0-701 to see the answer

You've previewed enough free SY0-701 questions. Unlock SY0-701 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Full SY0-701 Practice