CompTIA Security+ SY0-701 Investigation Data Sources Practice Test 1

 

Topic 22 Practice Test 1 covers Investigation Data Sources for CompTIA Security+ SY0-701 and maps to objective 4.9: Given a scenario, use data sources to support an investigation. For broader exam preparation, review the CompTIA Security+ Exam Dumps. Every option includes focused editorial reasoning explaining both the concept and its fit to the scenario.

Question 1

Which record is generated by an application describing requests, errors, authentication, transactions, or other program activity?

  1. Application log
  2. Endpoint log
  3. Metadata
  4. IDS/IPS log

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Application log means a record generated by an application describing requests, errors, authentication, transactions, or other program activity. That makes it the best answer here; Endpoint log addresses telemetry from endpoint security tools or operating environments describing processes, files, users, and device events, not the function requested in the stem.

Incorrect Answers

 

Answer B is incorrect because Endpoint log refers to telemetry from endpoint security tools or operating environments describing processes, files, users, and device events. The key mismatch is functional: Application log addresses a record generated by an application describing requests, errors, authentication, transactions, or other program activity, the need stated by the question.

Answer C is incorrect because Metadata refers to descriptive information about other data, such as timestamps, source, destination, ownership, or file attributes. The scenario instead requires a record generated by an application describing requests, errors, authentication, transactions, or other program activity, which is why Application log is the better answer; this option serves the different function defined above.

Answer D is incorrect because IDS/IPS log refers to a record of detection or prevention events produced by intrusion detection or prevention systems. That concept can be valid in another scenario, but this question is testing a record generated by an application describing requests, errors, authentication, transactions, or other program activity; Application log therefore fits the requirement more directly.

 

Question 2

An architect working on a digital investigation needs one capability that provides events from routers, switches, wireless controllers, or other network infrastructure and another that provides descriptive information about other data, such as timestamps, source, destination, ownership, or file attributes. Which TWO selections are the best match? Choose TWO.

  1. Application log
  2. Network-device log
  3. Endpoint log
  4. Metadata
  5. Operating-system security log

Correct Answers: B, D

Correct Answers

 

 

Answer B is correct because Network-device log means events from routers, switches, wireless controllers, or other network infrastructure. This option satisfies a specific requirement in the stem; Operating-system security log serves an operating-system record of events such as authentication, privilege use, policy changes, and system activity and therefore is not interchangeable with it.

Answer D is correct because Metadata means descriptive information about other data, such as timestamps, source, destination, ownership, or file attributes. This selection maps directly to one of the named needs. Application log addresses a record generated by an application describing requests, errors, authentication, transactions, or other program activity, so it does not satisfy the same slot.

Incorrect Answers

 

Answer A is incorrect because Application log means a record generated by an application describing requests, errors, authentication, transactions, or other program activity. The question requires exactly 2 selections: Network-device log, Metadata. This option falls outside that required set.

Answer C is incorrect because Endpoint log means telemetry from endpoint security tools or operating environments describing processes, files, users, and device events. The scenario calls for Network-device log, Metadata. Selecting this option would leave one of those required functions uncovered.

Answer E is incorrect because Operating-system security log means an operating-system record of events such as authentication, privilege use, policy changes, and system activity. The fixed-count answer set is Network-device log, Metadata; this option does not fill one of those named functions.

 

Question 3

To quickly review recurring security data in a standardized form, which security approach should be selected?

  1. Packet capture
  2. Operating-system security log
  3. Automated security report
  4. Vulnerability-scan result

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Automated security report means machine-generated summary of findings, trends, or security-control results. The requirement maps directly to this function, whereas Packet capture is aimed at recording of network packets for detailed protocol and content analysis.

Incorrect Answers

 

Answer A is incorrect because Packet capture refers to recording of network packets for detailed protocol and content analysis. That concept can be valid in another scenario, but this question is testing machine-generated summary of findings, trends, or security-control results; Automated security report therefore fits the requirement more directly.

Answer B is incorrect because Operating-system security log refers to an operating-system record of events such as authentication, privilege use, policy changes, and system activity. That concept can be valid in another scenario, but this question is testing machine-generated summary of findings, trends, or security-control results; Automated security report therefore fits the requirement more directly.

Answer D is incorrect because Vulnerability-scan result refers to assessment output identifying suspected weaknesses, versions, and affected systems. This could be appropriate elsewhere, but the required function is machine-generated summary of findings, trends, or security-control results; that makes Automated security report the precise choice.

 

Question 4

An investigator reviews a file’s owner and timestamps without examining its contents. Which category of information is being inspected?

  1. Application log
  2. Packet capture
  3. Metadata
  4. IDS/IPS log

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Metadata means descriptive information about other data, such as timestamps, source, destination, ownership, or file attributes. This matches the requirement as written. Application log can be valid in another context, but it is used for a record generated by an application describing requests, errors, authentication, transactions, or other program activity.

Incorrect Answers

 

Answer A is incorrect because Application log refers to a record generated by an application describing requests, errors, authentication, transactions, or other program activity. The key mismatch is functional: Metadata addresses descriptive information about other data, such as timestamps, source, destination, ownership, or file attributes, the need stated by the question.

Answer B is incorrect because Packet capture refers to recording of network packets for detailed protocol and content analysis. The scenario instead requires descriptive information about other data, such as timestamps, source, destination, ownership, or file attributes, which is why Metadata is the better answer; this option serves the different function defined above.

Answer D is incorrect because IDS/IPS log refers to a record of detection or prevention events produced by intrusion detection or prevention systems. The concept is valid, but it does not match this stem. The required function is descriptive information about other data, such as timestamps, source, destination, ownership, or file attributes, which maps to Metadata.

 

Question 5

An architect working on a digital investigation needs one capability that provides operating-system record of events such as authentication, privilege use, policy changes, and system activity and another that provides machine-generated summary of findings, trends, or security-control results. Which TWO selections are the best match? Choose TWO.

  1. Metadata
  2. Automated security report
  3. Operating-system security log
  4. Packet capture
  5. Security dashboard

Correct Answers: B, C

Correct Answers

 

 

Answer B is correct because Automated security report means machine-generated summary of findings, trends, or security-control results. It belongs in the fixed-count answer set because it covers one of the stated requirements. Metadata instead serves descriptive information about other data, such as timestamps, source, destination, ownership, or file attributes and cannot replace this function.

Answer C is correct because Operating-system security log means an operating-system record of events such as authentication, privilege use, policy changes, and system activity. This selection maps directly to one of the named needs. Metadata addresses descriptive information about other data, such as timestamps, source, destination, ownership, or file attributes, so it does not satisfy the same slot.

Incorrect Answers

 

Answer A is incorrect because Metadata means descriptive information about other data, such as timestamps, source, destination, ownership, or file attributes. Every answer slot must map to a stated requirement. The correct set is Automated security report, Operating-system security log, so this option cannot replace one of those selections.

Answer D is incorrect because Packet capture means recording of network packets for detailed protocol and content analysis. The fixed-count answer set is Automated security report, Operating-system security log; this option does not fill one of those named functions.

Answer E is incorrect because Security dashboard means visual interface summarizing current metrics, alerts, or operational status. The required choices are Automated security report, Operating-system security log. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

 

Question 6

To investigate suspicious activity on a workstation or server, which security approach should be selected?

  1. Network-device log
  2. Endpoint log
  3. Automated security report
  4. Operating-system security log

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Endpoint log means telemetry from endpoint security tools or operating environments describing processes, files, users, and device events. The deciding point is functional fit: this option covers the stated need, while Network-device log addresses events from routers, switches, wireless controllers, or other network infrastructure.

Incorrect Answers

 

Answer A is incorrect because Network-device log refers to events from routers, switches, wireless controllers, or other network infrastructure. This could be appropriate elsewhere, but the required function is telemetry from endpoint security tools or operating environments describing processes, files, users, and device events; that makes Endpoint log the precise choice.

Answer C is incorrect because Automated security report refers to machine-generated summary of findings, trends, or security-control results. The scenario instead requires telemetry from endpoint security tools or operating environments describing processes, files, users, and device events, which is why Endpoint log is the better answer; this option serves the different function defined above.

Answer D is incorrect because Operating-system security log refers to an operating-system record of events such as authentication, privilege use, policy changes, and system activity. The key mismatch is functional: Endpoint log addresses telemetry from endpoint security tools or operating environments describing processes, files, users, and device events, the need stated by the question.

 

Question 7

A connectivity incident follows an interface change and routing updates on network equipment. Which log is most likely to record these device events?

  1. Packet capture
  2. Vulnerability-scan result
  3. Automated security report
  4. Network-device log

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Network-device log means events from routers, switches, wireless controllers, or other network infrastructure. The deciding point is functional fit: this option covers the stated need, while Packet capture addresses recording of network packets for detailed protocol and content analysis.

Incorrect Answers

 

Answer A is incorrect because Packet capture refers to recording of network packets for detailed protocol and content analysis. The question is not asking for this function. It is testing events from routers, switches, wireless controllers, or other network infrastructure, so Network-device log is the stronger fit.

Answer B is incorrect because Vulnerability-scan result refers to assessment output identifying suspected weaknesses, versions, and affected systems. The key mismatch is functional: Network-device log addresses events from routers, switches, wireless controllers, or other network infrastructure, the need stated by the question.

Answer C is incorrect because Automated security report refers to machine-generated summary of findings, trends, or security-control results. The scenario instead requires events from routers, switches, wireless controllers, or other network infrastructure, which is why Network-device log is the better answer; this option serves the different function defined above.

 

Question 8

To trace identity and host security events, which security approach should be selected?

  1. IDS/IPS log
  2. Vulnerability-scan result
  3. Endpoint log
  4. Operating-system security log

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Operating-system security log means an operating-system record of events such as authentication, privilege use, policy changes, and system activity. This matches the requirement as written. Endpoint log can be valid in another context, but it is used for telemetry from endpoint security tools or operating environments describing processes, files, users, and device events.

Incorrect Answers

 

Answer A is incorrect because IDS/IPS log refers to a record of detection or prevention events produced by intrusion detection or prevention systems. The question is not asking for this function. It is testing an operating-system record of events such as authentication, privilege use, policy changes, and system activity, so Operating-system security log is the stronger fit.

Answer B is incorrect because Vulnerability-scan result refers to assessment output identifying suspected weaknesses, versions, and affected systems. The concept is valid, but it does not match this stem. The required function is an operating-system record of events such as authentication, privilege use, policy changes, and system activity, which maps to Operating-system security log.

Answer C is incorrect because Endpoint log refers to telemetry from endpoint security tools or operating environments describing processes, files, users, and device events. The question is not asking for this function. It is testing an operating-system record of events such as authentication, privilege use, policy changes, and system activity, so Operating-system security log is the stronger fit.

 

Question 9

A transaction failed inside a particular application, and the investigator needs the application’s own execution events. Which log should be examined first?

  1. Application log
  2. Automated security report
  3. Operating-system security log
  4. Endpoint log

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Application log means a record generated by an application describing requests, errors, authentication, transactions, or other program activity. That is the function the question is testing. Automated security report would instead be used for machine-generated summary of findings, trends, or security-control results.

Incorrect Answers

 

Answer B is incorrect because Automated security report refers to machine-generated summary of findings, trends, or security-control results. The question is not asking for this function. It is testing a record generated by an application describing requests, errors, authentication, transactions, or other program activity, so Application log is the stronger fit.

Answer C is incorrect because Operating-system security log refers to an operating-system record of events such as authentication, privilege use, policy changes, and system activity. The concept is valid, but it does not match this stem. The required function is a record generated by an application describing requests, errors, authentication, transactions, or other program activity, which maps to Application log.

Answer D is incorrect because Endpoint log refers to telemetry from endpoint security tools or operating environments describing processes, files, users, and device events. This could be appropriate elsewhere, but the required function is a record generated by an application describing requests, errors, authentication, transactions, or other program activity; that makes Application log the precise choice.

 

Question 10

What is a record of detection or prevention events produced by intrusion detection or prevention systems?

  1. Network-device log
  2. Vulnerability-scan result
  3. Application log
  4. IDS/IPS log

Correct Answer: D

Correct Answer

 

 

Answer D is correct because IDS/IPS log means a record of detection or prevention events produced by intrusion detection or prevention systems. This is the precise fit for the scenario. Network-device log serves the different purpose of events from routers, switches, wireless controllers, or other network infrastructure.

Incorrect Answers

 

Answer A is incorrect because Network-device log refers to events from routers, switches, wireless controllers, or other network infrastructure. That concept can be valid in another scenario, but this question is testing a record of detection or prevention events produced by intrusion detection or prevention systems; IDS/IPS log therefore fits the requirement more directly.

Answer B is incorrect because Vulnerability-scan result refers to assessment output identifying suspected weaknesses, versions, and affected systems. That concept can be valid in another scenario, but this question is testing a record of detection or prevention events produced by intrusion detection or prevention systems; IDS/IPS log therefore fits the requirement more directly.

Answer C is incorrect because Application log refers to a record generated by an application describing requests, errors, authentication, transactions, or other program activity. The key mismatch is functional: IDS/IPS log addresses a record of detection or prevention events produced by intrusion detection or prevention systems, the need stated by the question.

 

Question 11

An architect working on a digital investigation needs one capability that provides telemetry from endpoint security tools or operating environments describing processes, files, users, and device events and another that provides events from routers, switches, wireless controllers, or other network infrastructure. Which TWO selections are the best match? Choose TWO.

  1. Network-device log
  2. Endpoint log
  3. Operating-system security log
  4. IDS/IPS log
  5. Automated security report

Correct Answers: A, B

Correct Answers

 

 

Answer A is correct because Network-device log means events from routers, switches, wireless controllers, or other network infrastructure. It belongs in the fixed-count answer set because it covers one of the stated requirements. IDS/IPS log instead serves a record of detection or prevention events produced by intrusion detection or prevention systems and cannot replace this function.

Answer B is correct because Endpoint log means telemetry from endpoint security tools or operating environments describing processes, files, users, and device events. One required function is exactly what this option provides. Operating-system security log may be useful elsewhere, but it is used for an operating-system record of events such as authentication, privilege use, policy changes, and system activity.

Incorrect Answers

 

Answer C is incorrect because Operating-system security log means an operating-system record of events such as authentication, privilege use, policy changes, and system activity. The required choices are Endpoint log, Network-device log. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

Answer D is incorrect because IDS/IPS log means a record of detection or prevention events produced by intrusion detection or prevention systems. The fixed-count answer set is Endpoint log, Network-device log; this option does not fill one of those named functions.

Answer E is incorrect because Automated security report means machine-generated summary of findings, trends, or security-control results. Every answer slot must map to a stated requirement. The correct set is Endpoint log, Network-device log, so this option cannot replace one of those selections.

 

Question 12

Which term describes machine-generated summary of findings, trends, or security-control results?

  1. Vulnerability-scan result
  2. Firewall log
  3. Application log
  4. Automated security report

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Automated security report means machine-generated summary of findings, trends, or security-control results. That makes it the best answer here; Application log addresses a record generated by an application describing requests, errors, authentication, transactions, or other program activity, not the function requested in the stem.

Incorrect Answers

 

Answer A is incorrect because Vulnerability-scan result refers to assessment output identifying suspected weaknesses, versions, and affected systems. The key mismatch is functional: Automated security report addresses machine-generated summary of findings, trends, or security-control results, the need stated by the question.

Answer B is incorrect because Firewall log refers to a record of traffic decisions, sessions, rule matches, and related network-security events. This could be appropriate elsewhere, but the required function is machine-generated summary of findings, trends, or security-control results; that makes Automated security report the precise choice.

Answer C is incorrect because Application log refers to a record generated by an application describing requests, errors, authentication, transactions, or other program activity. The scenario instead requires machine-generated summary of findings, trends, or security-control results, which is why Automated security report is the better answer; this option serves the different function defined above.

 

Question 13

An investigation focuses on host authentication and operating-system security events. Which log is the most relevant starting point?

  1. Metadata
  2. Firewall log
  3. Operating-system security log
  4. Application log

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Operating-system security log means an operating-system record of events such as authentication, privilege use, policy changes, and system activity. The deciding point is functional fit: this option covers the stated need, while Application log addresses a record generated by an application describing requests, errors, authentication, transactions, or other program activity.

Incorrect Answers

 

Answer A is incorrect because Metadata refers to descriptive information about other data, such as timestamps, source, destination, ownership, or file attributes. This could be appropriate elsewhere, but the required function is an operating-system record of events such as authentication, privilege use, policy changes, and system activity; that makes Operating-system security log the precise choice.

Answer B is incorrect because Firewall log refers to a record of traffic decisions, sessions, rule matches, and related network-security events. The question is not asking for this function. It is testing an operating-system record of events such as authentication, privilege use, policy changes, and system activity, so Operating-system security log is the stronger fit.

Answer D is incorrect because Application log refers to a record generated by an application describing requests, errors, authentication, transactions, or other program activity. The key mismatch is functional: Operating-system security log addresses an operating-system record of events such as authentication, privilege use, policy changes, and system activity, the need stated by the question.

 

Question 14

The control set for a digital investigation must address both record generated by an application describing requests, errors, authentication, transactions, or other program activity and machine-generated summary of findings, trends, or security-control results. Which TWO choices map directly to those needs? Choose TWO.

  1. Application log
  2. Metadata
  3. Automated security report
  4. Vulnerability-scan result
  5. Endpoint log

Correct Answers: A, C

Correct Answers

 

 

Answer A is correct because Application log means a record generated by an application describing requests, errors, authentication, transactions, or other program activity. It belongs in the fixed-count answer set because it covers one of the stated requirements. Endpoint log instead serves telemetry from endpoint security tools or operating environments describing processes, files, users, and device events and cannot replace this function.

Answer C is correct because Automated security report means machine-generated summary of findings, trends, or security-control results. One required function is exactly what this option provides. Vulnerability-scan result may be useful elsewhere, but it is used for assessment output identifying suspected weaknesses, versions, and affected systems.

Incorrect Answers

 

Answer B is incorrect because Metadata means descriptive information about other data, such as timestamps, source, destination, ownership, or file attributes. The fixed-count answer set is Application log, Automated security report; this option does not fill one of those named functions.

Answer D is incorrect because Vulnerability-scan result means assessment output identifying suspected weaknesses, versions, and affected systems. Every answer slot must map to a stated requirement. The correct set is Application log, Automated security report, so this option cannot replace one of those selections.

Answer E is incorrect because Endpoint log means telemetry from endpoint security tools or operating environments describing processes, files, users, and device events. The scenario calls for Application log, Automated security report. Selecting this option would leave one of those required functions uncovered.

 

Question 15

During a digital investigation, three requirements must be addressed: (1) record of detection or prevention events produced by intrusion detection or prevention systems; (2) events from routers, switches, wireless controllers, or other network infrastructure; and (3) assessment output identifying suspected weaknesses, versions, and affected systems. Which THREE choices best satisfy them? Choose THREE.

  1. Network-device log
  2. Packet capture
  3. IDS/IPS log
  4. Security dashboard
  5. Vulnerability-scan result
  6. Metadata

Correct Answers: A, C, E

Correct Answers

 

 

Answer A is correct because Network-device log means events from routers, switches, wireless controllers, or other network infrastructure. This selection maps directly to one of the named needs. Security dashboard addresses visual interface summarizing current metrics, alerts, or operational status, so it does not satisfy the same slot.

Answer C is correct because IDS/IPS log means a record of detection or prevention events produced by intrusion detection or prevention systems. One required function is exactly what this option provides. Packet capture may be useful elsewhere, but it is used for recording of network packets for detailed protocol and content analysis.

Answer E is correct because Vulnerability-scan result means assessment output identifying suspected weaknesses, versions, and affected systems. One required function is exactly what this option provides. Metadata may be useful elsewhere, but it is used for descriptive information about other data, such as timestamps, source, destination, ownership, or file attributes.

Incorrect Answers

 

Answer B is incorrect because Packet capture means recording of network packets for detailed protocol and content analysis. The scenario calls for Vulnerability-scan result, IDS/IPS log, Network-device log. Selecting this option would leave one of those required functions uncovered.

Answer D is incorrect because Security dashboard means visual interface summarizing current metrics, alerts, or operational status. Every answer slot must map to a stated requirement. The correct set is Vulnerability-scan result, IDS/IPS log, Network-device log, so this option cannot replace one of those selections.

Answer F is incorrect because Metadata means descriptive information about other data, such as timestamps, source, destination, ownership, or file attributes. Every answer slot must map to a stated requirement. The correct set is Vulnerability-scan result, IDS/IPS log, Network-device log, so this option cannot replace one of those selections.

 

Question 16

Which term describes recording of network packets for detailed protocol and content analysis?

  1. Automated security report
  2. Packet capture
  3. Vulnerability-scan result
  4. Operating-system security log

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Packet capture means recording of network packets for detailed protocol and content analysis. That is the function the question is testing. Automated security report would instead be used for machine-generated summary of findings, trends, or security-control results.

Incorrect Answers

 

Answer A is incorrect because Automated security report refers to machine-generated summary of findings, trends, or security-control results. That concept can be valid in another scenario, but this question is testing recording of network packets for detailed protocol and content analysis; Packet capture therefore fits the requirement more directly.

Answer C is incorrect because Vulnerability-scan result refers to assessment output identifying suspected weaknesses, versions, and affected systems. The question is not asking for this function. It is testing recording of network packets for detailed protocol and content analysis, so Packet capture is the stronger fit.

Answer D is incorrect because Operating-system security log refers to an operating-system record of events such as authentication, privilege use, policy changes, and system activity. The concept is valid, but it does not match this stem. The required function is recording of network packets for detailed protocol and content analysis, which maps to Packet capture.

 

Question 17

To connect incident evidence with known exposures, which security approach should be selected?

  1. Vulnerability-scan result
  2. Application log
  3. Firewall log
  4. Network-device log

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Vulnerability-scan result means assessment output identifying suspected weaknesses, versions, and affected systems. This matches the requirement as written. Application log can be valid in another context, but it is used for a record generated by an application describing requests, errors, authentication, transactions, or other program activity.

Incorrect Answers

 

Answer B is incorrect because Application log refers to a record generated by an application describing requests, errors, authentication, transactions, or other program activity. The concept is valid, but it does not match this stem. The required function is assessment output identifying suspected weaknesses, versions, and affected systems, which maps to Vulnerability-scan result.

Answer C is incorrect because Firewall log refers to a record of traffic decisions, sessions, rule matches, and related network-security events. The concept is valid, but it does not match this stem. The required function is assessment output identifying suspected weaknesses, versions, and affected systems, which maps to Vulnerability-scan result.

Answer D is incorrect because Network-device log refers to events from routers, switches, wireless controllers, or other network infrastructure. This could be appropriate elsewhere, but the required function is assessment output identifying suspected weaknesses, versions, and affected systems; that makes Vulnerability-scan result the precise choice.

 

Question 18

Two requirements remain open in a digital investigation: record of traffic decisions, sessions, rule matches, and related network-security events; events from routers, switches, wireless controllers, or other network infrastructure. Which TWO options close those specific gaps? Choose TWO.

  1. Automated security report
  2. Metadata
  3. Packet capture
  4. Network-device log
  5. Firewall log

Correct Answers: D, E

Correct Answers

 

 

Answer D is correct because Network-device log means events from routers, switches, wireless controllers, or other network infrastructure. This selection maps directly to one of the named needs. Automated security report addresses machine-generated summary of findings, trends, or security-control results, so it does not satisfy the same slot.

Answer E is correct because Firewall log means a record of traffic decisions, sessions, rule matches, and related network-security events. This option satisfies a specific requirement in the stem; Packet capture serves recording of network packets for detailed protocol and content analysis and therefore is not interchangeable with it.

Incorrect Answers

 

Answer A is incorrect because Automated security report means machine-generated summary of findings, trends, or security-control results. The scenario calls for Firewall log, Network-device log. Selecting this option would leave one of those required functions uncovered. For example, Firewall log is required for a record of traffic decisions, sessions, rule matches, and related network-security events.

Answer B is incorrect because Metadata means descriptive information about other data, such as timestamps, source, destination, ownership, or file attributes. The question requires exactly 2 selections: Firewall log, Network-device log. This option falls outside that required set. For example, Firewall log is required for a record of traffic decisions, sessions, rule matches, and related network-security events.

Answer C is incorrect because Packet capture means recording of network packets for detailed protocol and content analysis. The question requires exactly 2 selections: Firewall log, Network-device log. This option falls outside that required set. For example, Network-device log is required for events from routers, switches, wireless controllers, or other network infrastructure.

 

Question 19

To inspect communication at a granular level when flow summaries are insufficient, which security approach should be selected?

  1. Application log
  2. Packet capture
  3. Endpoint log
  4. Network-device log

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Packet capture means recording of network packets for detailed protocol and content analysis. The requirement maps directly to this function, whereas Endpoint log is aimed at telemetry from endpoint security tools or operating environments describing processes, files, users, and device events.

Incorrect Answers

 

Answer A is incorrect because Application log refers to a record generated by an application describing requests, errors, authentication, transactions, or other program activity. This could be appropriate elsewhere, but the required function is recording of network packets for detailed protocol and content analysis; that makes Packet capture the precise choice.

Answer C is incorrect because Endpoint log refers to telemetry from endpoint security tools or operating environments describing processes, files, users, and device events. The key mismatch is functional: Packet capture addresses recording of network packets for detailed protocol and content analysis, the need stated by the question.

Answer D is incorrect because Network-device log refers to events from routers, switches, wireless controllers, or other network infrastructure. This could be appropriate elsewhere, but the required function is recording of network packets for detailed protocol and content analysis; that makes Packet capture the precise choice.

 

Question 20

To identify signatures, attack attempts, and enforcement actions, which security approach should be selected?

  1. IDS/IPS log
  2. Firewall log
  3. Vulnerability-scan result
  4. Security dashboard

Correct Answer: A

Correct Answer

 

 

Answer A is correct because IDS/IPS log means a record of detection or prevention events produced by intrusion detection or prevention systems. This matches the requirement as written. Firewall log can be valid in another context, but it is used for a record of traffic decisions, sessions, rule matches, and related network-security events.

Incorrect Answers

 

Answer B is incorrect because Firewall log refers to a record of traffic decisions, sessions, rule matches, and related network-security events. That concept can be valid in another scenario, but this question is testing a record of detection or prevention events produced by intrusion detection or prevention systems; IDS/IPS log therefore fits the requirement more directly.

Answer C is incorrect because Vulnerability-scan result refers to assessment output identifying suspected weaknesses, versions, and affected systems. The key mismatch is functional: IDS/IPS log addresses a record of detection or prevention events produced by intrusion detection or prevention systems, the need stated by the question.

Answer D is incorrect because Security dashboard refers to visual interface summarizing current metrics, alerts, or operational status. The question is not asking for this function. It is testing a record of detection or prevention events produced by intrusion detection or prevention systems, so IDS/IPS log is the stronger fit.

Leave a Reply

How It Works

img
Step 1. Choose Exam
on ExamLabs
Download IT Exams Questions & Answers
img
Step 2. Open Exam with
Avanset Exam Simulator
Press here to download VCE Exam Simulator that simulates real exam environment
img
Step 3. Study
& Pass
IT Exams Anywhere, Anytime!