How to Monitor Workstations and Servers for Unauthorized Changes?
Which of the following actions could a security engineer take to ensure workstations and servers are properly monitored for unauthorized changes and software?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests your ability to distinguish between centralized endpoint integrity controls and peripheral monitoring techniques, with the primary trap being the false assumption that endpoints only refers to client workstations rather than servers as well.
This question evaluates the most effective method for maintaining system integrity and detecting unapproved software across enterprise devices. The community unanimously confirms that centralized endpoint management software provides the comprehensive visibility and policy enforcement required.
Candidates frequently choose logging scheduled tasks or monitoring egress traffic, mistakenly equating narrow audit trails or perimeter network analysis with holistic system state monitoring and software inventory tracking.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Core Concept: Centralized Endpoint Management
The correct answer is D, installing endpoint management software (such as EDR, MDM, or EMM solutions). These platforms deliver centralized oversight of the configuration, software inventory, and behavioral baselines of all managed assets, including both workstations and servers. They continuously scan for unauthorized file modifications, registry tampering, and unapproved application deployments, triggering automated alerts and remediation workflows. Community feedback emphasizes that modern endpoint suites explicitly support server operating systems, effectively debunking the misconception that endpoint tools are limited to client devices.Why Distractors Fail
A. Log scheduled tasks: Task scheduling logs offer highly specific, narrow visibility into cron-like jobs. They do not capture broader system integrity violations, uninstalled software, or configuration drift, nor do they provide real-time enforcement capabilities. B. Monitor egress traffic: Network perimeter analysis focuses on data movement and potential exfiltration. It cannot inspect local file systems, track OS-level patches, or identify rogue applications running silently on the host. C. Block malicious signatures: Signature-based filtering is a reactive threat prevention measure. It stops known malware communications but lacks the proactive configuration auditing, software licensing tracking, and change management features required to ensure ongoing system integrity.Exam Context
CompTIA Security+ heavily weights centralized security operations. When a scenario demands cross-platform monitoring, policy enforcement, and change detection, endpoint management frameworks are invariably the intended solution over fragmented logging or network-centric tools.Official Reference
- CompTIA Security+ SY0-701 Official Objectives - Domain 4.2: Implement Host-Based Security Controls
- NIST SP 800-190 Application Container Security Guide
- ISO/IEC 27001:2022 Standard - Control 8.9: Configuration Management
Exam Strategy
When a question specifies monitoring across multiple device types (workstations and servers), immediately eliminate options limited to single-device categories or network perimeters. Prioritize centralized management platforms that combine asset discovery, policy enforcement, and continuous integrity validation, as these represent industry-standard compliance architectures.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →