Threat Detection — CompTIA Security+ (SY0-701) Practice Questions

Threat detection is the practice of identifying malicious activity or policy violations within an environment in a timely enough manner to limit damage. The SY0-701 exam addresses detection through multiple lenses: signature-based tools such as antivirus and intrusion detection systems, anomaly and behavior-based analytics, threat intelligence feeds, and user and entity behavior analytics. Candidates must understand detection strategies for common attack patterns including lateral movement, data exfiltration, and privilege escalation, as well as how detection capability feeds into the broader incident response lifecycle. Effective threat detection reduces dwell time, which is the interval between initial compromise and discovery, a key metric for measuring security program maturity.

Free questions on threat detection

What is the purpose of a Security Information and Event Management (SIEM) system?
Free question · easy · full answer + explanation
An organization experiences a sudden spike in outbound network traffic from several workstations to unknown IPs. Which attack is MOST likely occurring?
Free question · medium · full answer + explanation

More threat detection questions in the full bank

Practice CompTIA Security+ (SY0-701) Questions Free