How to Monitor Workstations and Servers for Unauthorized Changes?

Which of the following actions could a security engineer take to ensure workstations and servers are properly monitored for unauthorized changes and software?

  1. Configure all systems to log scheduled tasks.
  2. Collect and monitor all traffic exiting the network.
  3. Block traffic based on known malicious signatures.
  4. Install endpoint management software on all systems Source Reference Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests your ability to distinguish between centralized endpoint integrity controls and peripheral monitoring techniques, with the primary trap being the false assumption that endpoints only refers to client workstations rather than servers as well.

This question evaluates the most effective method for maintaining system integrity and detecting unapproved software across enterprise devices. The community unanimously confirms that centralized endpoint management software provides the comprehensive visibility and policy enforcement required.

Candidates frequently choose logging scheduled tasks or monitoring egress traffic, mistakenly equating narrow audit trails or perimeter network analysis with holistic system state monitoring and software inventory tracking.

Community Discussion (5 comments)

dbrowndiver 👍 6 Selected: D
Install endpoint management software on all systems is the correct answer because it offers a comprehensive solution for monitoring and managing workstations and servers. Endpoint management software provides visibility into unauthorized changes, detects unapproved software installations, and enforces security policies, making it the most effective choice for ensuring system integrity and compliance.
9149f41 👍 1 Selected: D
Why B is not correct: Collect and monitor all traffic exiting the network. The questions are all about hardware, not network. But the B is relevant with network traffic.
MaxiPrince 👍 1 Selected: D
Install endpoint management software on all systems
famuza77 👍 1
I thought Endpoints managent were only for workstations and no servers.
Shaman73 👍 4 Selected: D
D. Install endpoint management software on all systems

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Core Concept: Centralized Endpoint Management

The correct answer is D, installing endpoint management software (such as EDR, MDM, or EMM solutions). These platforms deliver centralized oversight of the configuration, software inventory, and behavioral baselines of all managed assets, including both workstations and servers. They continuously scan for unauthorized file modifications, registry tampering, and unapproved application deployments, triggering automated alerts and remediation workflows. Community feedback emphasizes that modern endpoint suites explicitly support server operating systems, effectively debunking the misconception that endpoint tools are limited to client devices.

Why Distractors Fail

A. Log scheduled tasks: Task scheduling logs offer highly specific, narrow visibility into cron-like jobs. They do not capture broader system integrity violations, uninstalled software, or configuration drift, nor do they provide real-time enforcement capabilities. B. Monitor egress traffic: Network perimeter analysis focuses on data movement and potential exfiltration. It cannot inspect local file systems, track OS-level patches, or identify rogue applications running silently on the host. C. Block malicious signatures: Signature-based filtering is a reactive threat prevention measure. It stops known malware communications but lacks the proactive configuration auditing, software licensing tracking, and change management features required to ensure ongoing system integrity.

Exam Context

CompTIA Security+ heavily weights centralized security operations. When a scenario demands cross-platform monitoring, policy enforcement, and change detection, endpoint management frameworks are invariably the intended solution over fragmented logging or network-centric tools.

Official Reference

  • CompTIA Security+ SY0-701 Official Objectives - Domain 4.2: Implement Host-Based Security Controls
  • NIST SP 800-190 Application Container Security Guide
  • ISO/IEC 27001:2022 Standard - Control 8.9: Configuration Management

Exam Strategy

When a question specifies monitoring across multiple device types (workstations and servers), immediately eliminate options limited to single-device categories or network perimeters. Prioritize centralized management platforms that combine asset discovery, policy enforcement, and continuous integrity validation, as these represent industry-standard compliance architectures.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide