nerdexam
CompTIA

SY0-701 · Question #623

A company captures log-in details and reviews them each week to identify conditions such as excessive log-in attempts and frequent lockouts. Which of the following should a security analyst…

The correct answer is B. Adding automated alerting when anomalies occur. Automated alerting (B) directly improves security compliance monitoring by detecting and escalating anomalies - like brute-force attempts or lockouts - in real time rather than waiting a week for a human review, which dramatically reduces the window of exposure. Why the…

Submitted by andreas_gr· Mar 6, 2026Security operations

Question

A company captures log-in details and reviews them each week to identify conditions such as excessive log-in attempts and frequent lockouts. Which of the following should a security analyst recommend to improve security compliance monitoring?

Options

  • AIncluding the date and person who reviewed the information in a report
  • BAdding automated alerting when anomalies occur
  • CRequiring a statement each week that no exceptions were noted
  • DMasking the username in a report to protect privacy

How the community answered

(24 responses)
  • A
    13% (3)
  • B
    79% (19)
  • C
    4% (1)
  • D
    4% (1)

Explanation

Automated alerting (B) directly improves security compliance monitoring by detecting and escalating anomalies - like brute-force attempts or lockouts - in real time rather than waiting a week for a human review, which dramatically reduces the window of exposure.

Why the distractors are wrong:

  • A (documenting reviewer/date) improves audit trail accountability but doesn't enhance the detection or monitoring capability itself.
  • C (weekly "no exceptions" statement) adds a procedural checkbox but doesn't make monitoring more effective - it's documentation theater, not detection.
  • D (masking usernames) addresses privacy, not security monitoring; you actually need usernames to investigate suspicious activity meaningfully.

Memory tip: Think of the word monitoring as implying continuous oversight. If a solution only helps after the weekly review cycle, it's improving reporting or documentation - not monitoring. Automated alerting is the only option that closes the time gap between an event occurring and someone acting on it.

Topics

#Security monitoring#Automated alerting#Log analysis#Compliance monitoring

Community Discussion

No community discussion yet for this question.

Full SY0-701 Practice