Topic 22 Practice Test 2 covers Investigation Data Sources for CompTIA Security+ SY0-701 and maps to objective 4.9: Given a scenario, use data sources to support an investigation. For broader exam preparation, review the CompTIA Security+ Exam Dumps. Every option includes focused editorial reasoning explaining both the concept and its fit to the scenario.
Question 1
Reviewers working through a digital investigation identify three separate needs: record generated by an application describing requests, errors, authentication, transactions, or other program activity; operating-system record of events such as authentication, privilege use, policy changes, and system activity; assessment output identifying suspected weaknesses, versions, and affected systems. Which THREE choices map to those needs? Choose THREE.
- Application log
- Metadata
- Operating-system security log
- Firewall log
- Automated security report
- Vulnerability-scan result
Correct Answers: A, C, F
Correct Answers
Answer A is correct because Application log means a record generated by an application describing requests, errors, authentication, transactions, or other program activity. The fixed-count item needs this function in the answer set. Metadata covers descriptive information about other data, such as timestamps, source, destination, ownership, or file attributes, a different requirement.
Answer C is correct because Operating-system security log means an operating-system record of events such as authentication, privilege use, policy changes, and system activity. It belongs in the fixed-count answer set because it covers one of the stated requirements. Metadata instead serves descriptive information about other data, such as timestamps, source, destination, ownership, or file attributes and cannot replace this function.
Answer F is correct because Vulnerability-scan result means assessment output identifying suspected weaknesses, versions, and affected systems. This selection maps directly to one of the named needs. Firewall log addresses a record of traffic decisions, sessions, rule matches, and related network-security events, so it does not satisfy the same slot.
Incorrect Answers
Answer B is incorrect because Metadata means descriptive information about other data, such as timestamps, source, destination, ownership, or file attributes. The required choices are Operating-system security log, Vulnerability-scan result, Application log. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Answer D is incorrect because Firewall log means a record of traffic decisions, sessions, rule matches, and related network-security events. The fixed-count answer set is Operating-system security log, Vulnerability-scan result, Application log; this option does not fill one of those named functions.
Answer E is incorrect because Automated security report means machine-generated summary of findings, trends, or security-control results. The required choices are Operating-system security log, Vulnerability-scan result, Application log. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Question 2
During a digital investigation, the team has two independent requirements: (1) assessment output identifying suspected weaknesses, versions, and affected systems; and (2) recording of network packets for detailed protocol and content analysis. Which TWO choices best satisfy those requirements? Choose TWO.
- Vulnerability-scan result
- Security dashboard
- Endpoint log
- Packet capture
- Metadata
Correct Answers: A, D
Correct Answers
Answer A is correct because Vulnerability-scan result means assessment output identifying suspected weaknesses, versions, and affected systems. One required function is exactly what this option provides. Endpoint log may be useful elsewhere, but it is used for telemetry from endpoint security tools or operating environments describing processes, files, users, and device events.
Answer D is correct because Packet capture means recording of network packets for detailed protocol and content analysis. It belongs in the fixed-count answer set because it covers one of the stated requirements. Metadata instead serves descriptive information about other data, such as timestamps, source, destination, ownership, or file attributes and cannot replace this function.
Incorrect Answers
Answer B is incorrect because Security dashboard means visual interface summarizing current metrics, alerts, or operational status. The scenario calls for Vulnerability-scan result, Packet capture. Selecting this option would leave one of those required functions uncovered. For example, Vulnerability-scan result is required for assessment output identifying suspected weaknesses, versions, and affected systems.
Answer C is incorrect because Endpoint log means telemetry from endpoint security tools or operating environments describing processes, files, users, and device events. The fixed-count answer set is Vulnerability-scan result, Packet capture; this option does not fill one of those named functions.
Answer E is incorrect because Metadata means descriptive information about other data, such as timestamps, source, destination, ownership, or file attributes. The scenario calls for Vulnerability-scan result, Packet capture. Selecting this option would leave one of those required functions uncovered.
Question 3
To investigate interface changes, routing events, authentication, and connectivity issues, which security approach should be selected?
- Metadata
- Packet capture
- Application log
- Network-device log
Correct Answer: D
Correct Answer
Answer D is correct because Network-device log means events from routers, switches, wireless controllers, or other network infrastructure. This matches the requirement as written. Application log can be valid in another context, but it is used for a record generated by an application describing requests, errors, authentication, transactions, or other program activity.
Incorrect Answers
Answer A is incorrect because Metadata refers to descriptive information about other data, such as timestamps, source, destination, ownership, or file attributes. That concept can be valid in another scenario, but this question is testing events from routers, switches, wireless controllers, or other network infrastructure; Network-device log therefore fits the requirement more directly.
Answer B is incorrect because Packet capture refers to recording of network packets for detailed protocol and content analysis. The key mismatch is functional: Network-device log addresses events from routers, switches, wireless controllers, or other network infrastructure, the need stated by the question.
Answer C is incorrect because Application log refers to a record generated by an application describing requests, errors, authentication, transactions, or other program activity. This could be appropriate elsewhere, but the required function is events from routers, switches, wireless controllers, or other network infrastructure; that makes Network-device log the precise choice.
Question 4
An architect working on a digital investigation needs one capability that provides descriptive information about other data, such as timestamps, source, destination, ownership, or file attributes and another that provides machine-generated summary of findings, trends, or security-control results. Which TWO selections are the best match? Choose TWO.
- Vulnerability-scan result
- Operating-system security log
- Metadata
- Packet capture
- Automated security report
Correct Answers: C, E
Correct Answers
Answer C is correct because Metadata means descriptive information about other data, such as timestamps, source, destination, ownership, or file attributes. This option satisfies a specific requirement in the stem; Packet capture serves recording of network packets for detailed protocol and content analysis and therefore is not interchangeable with it.
Answer E is correct because Automated security report means machine-generated summary of findings, trends, or security-control results. This selection maps directly to one of the named needs. Packet capture addresses recording of network packets for detailed protocol and content analysis, so it does not satisfy the same slot.
Incorrect Answers
Answer A is incorrect because Vulnerability-scan result means assessment output identifying suspected weaknesses, versions, and affected systems. The fixed-count answer set is Automated security report, Metadata; this option does not fill one of those named functions. For example, Automated security report is required for machine-generated summary of findings, trends, or security-control results.
Answer B is incorrect because Operating-system security log means an operating-system record of events such as authentication, privilege use, policy changes, and system activity. The question requires exactly 2 selections: Automated security report, Metadata. This option falls outside that required set.
Answer D is incorrect because Packet capture means recording of network packets for detailed protocol and content analysis. The scenario calls for Automated security report, Metadata. Selecting this option would leave one of those required functions uncovered. For example, Metadata is required for descriptive information about other data, such as timestamps, source, destination, ownership, or file attributes.
Question 5
Which term describes telemetry from endpoint security tools or operating environments describing processes, files, users, and device events?
- Operating-system security log
- Endpoint log
- Firewall log
- IDS/IPS log
Correct Answer: B
Correct Answer
Answer B is correct because Endpoint log means telemetry from endpoint security tools or operating environments describing processes, files, users, and device events. The deciding point is functional fit: this option covers the stated need, while Operating-system security log addresses an operating-system record of events such as authentication, privilege use, policy changes, and system activity.
Incorrect Answers
Answer A is incorrect because Operating-system security log refers to an operating-system record of events such as authentication, privilege use, policy changes, and system activity. The concept is valid, but it does not match this stem. The required function is telemetry from endpoint security tools or operating environments describing processes, files, users, and device events, which maps to Endpoint log.
Answer C is incorrect because Firewall log refers to a record of traffic decisions, sessions, rule matches, and related network-security events. The key mismatch is functional: Endpoint log addresses telemetry from endpoint security tools or operating environments describing processes, files, users, and device events, the need stated by the question.
Answer D is incorrect because IDS/IPS log refers to a record of detection or prevention events produced by intrusion detection or prevention systems. The question is not asking for this function. It is testing telemetry from endpoint security tools or operating environments describing processes, files, users, and device events, so Endpoint log is the stronger fit.
Question 6
To determine which connections were allowed, denied, or inspected at a firewall, which security approach should be selected?
- Metadata
- Firewall log
- IDS/IPS log
- Packet capture
Correct Answer: B
Correct Answer
Answer B is correct because Firewall log means a record of traffic decisions, sessions, rule matches, and related network-security events. That is the function the question is testing. IDS/IPS log would instead be used for a record of detection or prevention events produced by intrusion detection or prevention systems.
Incorrect Answers
Answer A is incorrect because Metadata refers to descriptive information about other data, such as timestamps, source, destination, ownership, or file attributes. The key mismatch is functional: Firewall log addresses a record of traffic decisions, sessions, rule matches, and related network-security events, the need stated by the question.
Answer C is incorrect because IDS/IPS log refers to a record of detection or prevention events produced by intrusion detection or prevention systems. The key mismatch is functional: Firewall log addresses a record of traffic decisions, sessions, rule matches, and related network-security events, the need stated by the question.
Answer D is incorrect because Packet capture refers to recording of network packets for detailed protocol and content analysis. The key mismatch is functional: Firewall log addresses a record of traffic decisions, sessions, rule matches, and related network-security events, the need stated by the question.
Question 7
To correlate events and establish context without relying only on content, which security approach should be selected?
- Vulnerability-scan result
- Firewall log
- Packet capture
- Metadata
Correct Answer: D
Correct Answer
Answer D is correct because Metadata means descriptive information about other data, such as timestamps, source, destination, ownership, or file attributes. This matches the requirement as written. Packet capture can be valid in another context, but it is used for recording of network packets for detailed protocol and content analysis.
Incorrect Answers
Answer A is incorrect because Vulnerability-scan result refers to assessment output identifying suspected weaknesses, versions, and affected systems. That concept can be valid in another scenario, but this question is testing descriptive information about other data, such as timestamps, source, destination, ownership, or file attributes; Metadata therefore fits the requirement more directly.
Answer B is incorrect because Firewall log refers to a record of traffic decisions, sessions, rule matches, and related network-security events. The scenario instead requires descriptive information about other data, such as timestamps, source, destination, ownership, or file attributes, which is why Metadata is the better answer; this option serves the different function defined above.
Answer C is incorrect because Packet capture refers to recording of network packets for detailed protocol and content analysis. The key mismatch is functional: Metadata addresses descriptive information about other data, such as timestamps, source, destination, ownership, or file attributes, the need stated by the question.
Question 8
An investigator needs evidence of which network connections matched allow or deny rules at a security boundary. Which log is the most direct source?
- Packet capture
- Endpoint log
- Firewall log
- Network-device log
Correct Answer: C
Correct Answer
Answer C is correct because Firewall log means a record of traffic decisions, sessions, rule matches, and related network-security events. That makes it the best answer here; Network-device log addresses events from routers, switches, wireless controllers, or other network infrastructure, not the function requested in the stem.
Incorrect Answers
Answer A is incorrect because Packet capture refers to recording of network packets for detailed protocol and content analysis. The question is not asking for this function. It is testing a record of traffic decisions, sessions, rule matches, and related network-security events, so Firewall log is the stronger fit.
Answer B is incorrect because Endpoint log refers to telemetry from endpoint security tools or operating environments describing processes, files, users, and device events. The scenario instead requires a record of traffic decisions, sessions, rule matches, and related network-security events, which is why Firewall log is the better answer; this option serves the different function defined above.
Answer D is incorrect because Network-device log refers to events from routers, switches, wireless controllers, or other network infrastructure. The scenario instead requires a record of traffic decisions, sessions, rule matches, and related network-security events, which is why Firewall log is the better answer; this option serves the different function defined above.
Question 9
A security analyst needs device-level evidence about processes, files and user activity collected by endpoint tooling. Which log category supplies this telemetry?
- Endpoint log
- Metadata
- Security dashboard
- Operating-system security log
Correct Answer: A
Correct Answer
Answer A is correct because Endpoint log means telemetry from endpoint security tools or operating environments describing processes, files, users, and device events. This is the precise fit for the scenario. Security dashboard serves the different purpose of visual interface summarizing current metrics, alerts, or operational status.
Incorrect Answers
Answer B is incorrect because Metadata refers to descriptive information about other data, such as timestamps, source, destination, ownership, or file attributes. This could be appropriate elsewhere, but the required function is telemetry from endpoint security tools or operating environments describing processes, files, users, and device events; that makes Endpoint log the precise choice.
Answer C is incorrect because Security dashboard refers to visual interface summarizing current metrics, alerts, or operational status. The question is not asking for this function. It is testing telemetry from endpoint security tools or operating environments describing processes, files, users, and device events, so Endpoint log is the stronger fit.
Answer D is incorrect because Operating-system security log refers to an operating-system record of events such as authentication, privilege use, policy changes, and system activity. The key mismatch is functional: Endpoint log addresses telemetry from endpoint security tools or operating environments describing processes, files, users, and device events, the need stated by the question. This question specifically tests the requirement represented by Endpoint log.
Question 10
A review during a digital investigation identifies two gaps. One requires events from routers, switches, wireless controllers, or other network infrastructure. The other requires recording of network packets for detailed protocol and content analysis. Which TWO options should be included in the remediation plan? Choose TWO.
- Network-device log
- Automated security report
- Packet capture
- Endpoint log
- Vulnerability-scan result
Correct Answers: A, C
Correct Answers
Answer A is correct because Network-device log means events from routers, switches, wireless controllers, or other network infrastructure. This selection maps directly to one of the named needs. Vulnerability-scan result addresses assessment output identifying suspected weaknesses, versions, and affected systems, so it does not satisfy the same slot.
Answer C is correct because Packet capture means recording of network packets for detailed protocol and content analysis. This option satisfies a specific requirement in the stem; Vulnerability-scan result serves assessment output identifying suspected weaknesses, versions, and affected systems and therefore is not interchangeable with it.
Incorrect Answers
Answer B is incorrect because Automated security report means machine-generated summary of findings, trends, or security-control results. The scenario calls for Packet capture, Network-device log. Selecting this option would leave one of those required functions uncovered. For example, Network-device log is required for events from routers, switches, wireless controllers, or other network infrastructure.
Answer D is incorrect because Endpoint log means telemetry from endpoint security tools or operating environments describing processes, files, users, and device events. Every answer slot must map to a stated requirement. The correct set is Packet capture, Network-device log, so this option cannot replace one of those selections.
Answer E is incorrect because Vulnerability-scan result means assessment output identifying suspected weaknesses, versions, and affected systems. The question requires exactly 2 selections: Packet capture, Network-device log. This option falls outside that required set. For example, Network-device log is required for events from routers, switches, wireless controllers, or other network infrastructure.
Question 11
What is an operating-system record of events such as authentication, privilege use, policy changes, and system activity?
- Vulnerability-scan result
- Operating-system security log
- IDS/IPS log
- Endpoint log
Correct Answer: B
Correct Answer
Answer B is correct because Operating-system security log means an operating-system record of events such as authentication, privilege use, policy changes, and system activity. That is the function the question is testing. IDS/IPS log would instead be used for a record of detection or prevention events produced by intrusion detection or prevention systems.
Incorrect Answers
Answer A is incorrect because Vulnerability-scan result refers to assessment output identifying suspected weaknesses, versions, and affected systems. That concept can be valid in another scenario, but this question is testing an operating-system record of events such as authentication, privilege use, policy changes, and system activity; Operating-system security log therefore fits the requirement more directly.
Answer C is incorrect because IDS/IPS log refers to a record of detection or prevention events produced by intrusion detection or prevention systems. That concept can be valid in another scenario, but this question is testing an operating-system record of events such as authentication, privilege use, policy changes, and system activity; Operating-system security log therefore fits the requirement more directly.
Answer D is incorrect because Endpoint log refers to telemetry from endpoint security tools or operating environments describing processes, files, users, and device events. The question is not asking for this function. It is testing an operating-system record of events such as authentication, privilege use, policy changes, and system activity, so Operating-system security log is the stronger fit. This question specifically tests the requirement represented by Operating-system security log.
Question 12
Which term describes visual interface summarizing current metrics, alerts, or operational status?
- Security dashboard
- Packet capture
- Firewall log
- Operating-system security log
Correct Answer: A
Correct Answer
Answer A is correct because Security dashboard means visual interface summarizing current metrics, alerts, or operational status. The requirement maps directly to this function, whereas Firewall log is aimed at a record of traffic decisions, sessions, rule matches, and related network-security events.
Incorrect Answers
Answer B is incorrect because Packet capture refers to recording of network packets for detailed protocol and content analysis. This could be appropriate elsewhere, but the required function is visual interface summarizing current metrics, alerts, or operational status; that makes Security dashboard the precise choice.
Answer C is incorrect because Firewall log refers to a record of traffic decisions, sessions, rule matches, and related network-security events. The question is not asking for this function. It is testing visual interface summarizing current metrics, alerts, or operational status, so Security dashboard is the stronger fit.
Answer D is incorrect because Operating-system security log refers to an operating-system record of events such as authentication, privilege use, policy changes, and system activity. That concept can be valid in another scenario, but this question is testing visual interface summarizing current metrics, alerts, or operational status; Security dashboard therefore fits the requirement more directly.
Question 13
To spot patterns and prioritize investigation across multiple data sources, which security approach should be selected?
- Endpoint log
- Security dashboard
- Operating-system security log
- Application log
Correct Answer: B
Correct Answer
Answer B is correct because Security dashboard means visual interface summarizing current metrics, alerts, or operational status. The deciding point is functional fit: this option covers the stated need, while Operating-system security log addresses an operating-system record of events such as authentication, privilege use, policy changes, and system activity.
Incorrect Answers
Answer A is incorrect because Endpoint log refers to telemetry from endpoint security tools or operating environments describing processes, files, users, and device events. The scenario instead requires visual interface summarizing current metrics, alerts, or operational status, which is why Security dashboard is the better answer; this option serves the different function defined above.
Answer C is incorrect because Operating-system security log refers to an operating-system record of events such as authentication, privilege use, policy changes, and system activity. That concept can be valid in another scenario, but this question is testing visual interface summarizing current metrics, alerts, or operational status; Security dashboard therefore fits the requirement more directly. This question specifically tests the requirement represented by Security dashboard.
Answer D is incorrect because Application log refers to a record generated by an application describing requests, errors, authentication, transactions, or other program activity. The scenario instead requires visual interface summarizing current metrics, alerts, or operational status, which is why Security dashboard is the better answer; this option serves the different function defined above.
Question 14
Incident evidence suggests exploitation of a known weakness. Which assessment output should the analyst consult to determine whether the affected system had that exposure?
- Vulnerability-scan result
- Automated security report
- Security dashboard
- Operating-system security log
Correct Answer: A
Correct Answer
Answer A is correct because Vulnerability-scan result means assessment output identifying suspected weaknesses, versions, and affected systems. That makes it the best answer here; Automated security report addresses machine-generated summary of findings, trends, or security-control results, not the function requested in the stem.
Incorrect Answers
Answer B is incorrect because Automated security report refers to machine-generated summary of findings, trends, or security-control results. The scenario instead requires assessment output identifying suspected weaknesses, versions, and affected systems, which is why Vulnerability-scan result is the better answer; this option serves the different function defined above.
Answer C is incorrect because Security dashboard refers to visual interface summarizing current metrics, alerts, or operational status. The scenario instead requires assessment output identifying suspected weaknesses, versions, and affected systems, which is why Vulnerability-scan result is the better answer; this option serves the different function defined above.
Answer D is incorrect because Operating-system security log refers to an operating-system record of events such as authentication, privilege use, policy changes, and system activity. That concept can be valid in another scenario, but this question is testing assessment output identifying suspected weaknesses, versions, and affected systems; Vulnerability-scan result therefore fits the requirement more directly.
Question 15
During a digital investigation, the team has two independent requirements: (1) record of traffic decisions, sessions, rule matches, and related network-security events; and (2) telemetry from endpoint security tools or operating environments describing processes, files, users, and device events. Which TWO choices best satisfy those requirements? Choose TWO.
- Endpoint log
- IDS/IPS log
- Firewall log
- Automated security report
- Operating-system security log
Correct Answers: A, C
Correct Answers
Answer A is correct because Endpoint log means telemetry from endpoint security tools or operating environments describing processes, files, users, and device events. This selection maps directly to one of the named needs. Automated security report addresses machine-generated summary of findings, trends, or security-control results, so it does not satisfy the same slot.
Answer C is correct because Firewall log means a record of traffic decisions, sessions, rule matches, and related network-security events. One required function is exactly what this option provides. Operating-system security log may be useful elsewhere, but it is used for an operating-system record of events such as authentication, privilege use, policy changes, and system activity.
Incorrect Answers
Answer B is incorrect because IDS/IPS log means a record of detection or prevention events produced by intrusion detection or prevention systems. The scenario calls for Endpoint log, Firewall log. Selecting this option would leave one of those required functions uncovered.
Answer D is incorrect because Automated security report means machine-generated summary of findings, trends, or security-control results. The scenario calls for Endpoint log, Firewall log. Selecting this option would leave one of those required functions uncovered. For example, Endpoint log is required for telemetry from endpoint security tools or operating environments describing processes, files, users, and device events.
Answer E is incorrect because Operating-system security log means an operating-system record of events such as authentication, privilege use, policy changes, and system activity. Every answer slot must map to a stated requirement. The correct set is Endpoint log, Firewall log, so this option cannot replace one of those selections.
Question 16
A review during a digital investigation identifies two gaps. One requires record generated by an application describing requests, errors, authentication, transactions, or other program activity. The other requires recording of network packets for detailed protocol and content analysis. Which TWO options should be included in the remediation plan? Choose TWO.
- Packet capture
- Metadata
- Security dashboard
- Network-device log
- Application log
Correct Answers: A, E
Correct Answers
Answer A is correct because Packet capture means recording of network packets for detailed protocol and content analysis. One required function is exactly what this option provides. Security dashboard may be useful elsewhere, but it is used for visual interface summarizing current metrics, alerts, or operational status.
Answer E is correct because Application log means a record generated by an application describing requests, errors, authentication, transactions, or other program activity. It belongs in the fixed-count answer set because it covers one of the stated requirements. Security dashboard instead serves visual interface summarizing current metrics, alerts, or operational status and cannot replace this function.
Incorrect Answers
Answer B is incorrect because Metadata means descriptive information about other data, such as timestamps, source, destination, ownership, or file attributes. The question requires exactly 2 selections: Application log, Packet capture. This option falls outside that required set. For example, Application log is required for a record generated by an application describing requests, errors, authentication, transactions, or other program activity.
Answer C is incorrect because Security dashboard means visual interface summarizing current metrics, alerts, or operational status. The question requires exactly 2 selections: Application log, Packet capture. This option falls outside that required set. For example, Application log is required for a record generated by an application describing requests, errors, authentication, transactions, or other program activity.
Answer D is incorrect because Network-device log means events from routers, switches, wireless controllers, or other network infrastructure. The question requires exactly 2 selections: Application log, Packet capture. This option falls outside that required set. For example, Application log is required for a record generated by an application describing requests, errors, authentication, transactions, or other program activity.
Question 17
Which term describes events from routers, switches, wireless controllers, or other network infrastructure?
- Network-device log
- Firewall log
- Security dashboard
- Endpoint log
Correct Answer: A
Correct Answer
Answer A is correct because Network-device log means events from routers, switches, wireless controllers, or other network infrastructure. That makes it the best answer here; Firewall log addresses a record of traffic decisions, sessions, rule matches, and related network-security events, not the function requested in the stem.
Incorrect Answers
Answer B is incorrect because Firewall log refers to a record of traffic decisions, sessions, rule matches, and related network-security events. This could be appropriate elsewhere, but the required function is events from routers, switches, wireless controllers, or other network infrastructure; that makes Network-device log the precise choice.
Answer C is incorrect because Security dashboard refers to visual interface summarizing current metrics, alerts, or operational status. This could be appropriate elsewhere, but the required function is events from routers, switches, wireless controllers, or other network infrastructure; that makes Network-device log the precise choice.
Answer D is incorrect because Endpoint log refers to telemetry from endpoint security tools or operating environments describing processes, files, users, and device events. That concept can be valid in another scenario, but this question is testing events from routers, switches, wireless controllers, or other network infrastructure; Network-device log therefore fits the requirement more directly.
Question 18
To reconstruct what happened inside a specific application, which security approach should be selected?
- Vulnerability-scan result
- Security dashboard
- Application log
- Operating-system security log
Correct Answer: C
Correct Answer
Answer C is correct because Application log means a record generated by an application describing requests, errors, authentication, transactions, or other program activity. That is the function the question is testing. Operating-system security log would instead be used for an operating-system record of events such as authentication, privilege use, policy changes, and system activity.
Incorrect Answers
Answer A is incorrect because Vulnerability-scan result refers to assessment output identifying suspected weaknesses, versions, and affected systems. The key mismatch is functional: Application log addresses a record generated by an application describing requests, errors, authentication, transactions, or other program activity, the need stated by the question.
Answer B is incorrect because Security dashboard refers to visual interface summarizing current metrics, alerts, or operational status. The concept is valid, but it does not match this stem. The required function is a record generated by an application describing requests, errors, authentication, transactions, or other program activity, which maps to Application log.
Answer D is incorrect because Operating-system security log refers to an operating-system record of events such as authentication, privilege use, policy changes, and system activity. That concept can be valid in another scenario, but this question is testing a record generated by an application describing requests, errors, authentication, transactions, or other program activity; Application log therefore fits the requirement more directly.
Question 19
Which term describes descriptive information about other data, such as timestamps, source, destination, ownership, or file attributes?
- Application log
- Automated security report
- Metadata
- Vulnerability-scan result
Correct Answer: C
Correct Answer
Answer C is correct because Metadata means descriptive information about other data, such as timestamps, source, destination, ownership, or file attributes. That is the function the question is testing. Vulnerability-scan result would instead be used for assessment output identifying suspected weaknesses, versions, and affected systems.
Incorrect Answers
Answer A is incorrect because Application log refers to a record generated by an application describing requests, errors, authentication, transactions, or other program activity. The key mismatch is functional: Metadata addresses descriptive information about other data, such as timestamps, source, destination, ownership, or file attributes, the need stated by the question. This question specifically tests the requirement represented by Metadata.
Answer B is incorrect because Automated security report refers to machine-generated summary of findings, trends, or security-control results. The concept is valid, but it does not match this stem. The required function is descriptive information about other data, such as timestamps, source, destination, ownership, or file attributes, which maps to Metadata.
Answer D is incorrect because Vulnerability-scan result refers to assessment output identifying suspected weaknesses, versions, and affected systems. This could be appropriate elsewhere, but the required function is descriptive information about other data, such as timestamps, source, destination, ownership, or file attributes; that makes Metadata the precise choice.
Question 20
An analyst needs the events explaining why an intrusion sensor generated an alert or blocked traffic. Which log records those detection or prevention actions?
- Application log
- Vulnerability-scan result
- Endpoint log
- IDS/IPS log
Correct Answer: D
Correct Answer
Answer D is correct because IDS/IPS log means a record of detection or prevention events produced by intrusion detection or prevention systems. The deciding point is functional fit: this option covers the stated need, while Endpoint log addresses telemetry from endpoint security tools or operating environments describing processes, files, users, and device events.
Incorrect Answers
Answer A is incorrect because Application log refers to a record generated by an application describing requests, errors, authentication, transactions, or other program activity. This could be appropriate elsewhere, but the required function is a record of detection or prevention events produced by intrusion detection or prevention systems; that makes IDS/IPS log the precise choice.
Answer B is incorrect because Vulnerability-scan result refers to assessment output identifying suspected weaknesses, versions, and affected systems. The scenario instead requires a record of detection or prevention events produced by intrusion detection or prevention systems, which is why IDS/IPS log is the better answer; this option serves the different function defined above.
Answer C is incorrect because Endpoint log refers to telemetry from endpoint security tools or operating environments describing processes, files, users, and device events. The key mismatch is functional: IDS/IPS log addresses a record of detection or prevention events produced by intrusion detection or prevention systems, the need stated by the question.