CompTIA Security+ SY0-701 Investigation Data Sources Practice Test

 

Topic 22 focuses on Investigation Data Sources for the CompTIA Security+ certification and the SY0-701 exam, using practical cybersecurity scenarios aligned to the published Security+ objectives. For broader exam preparation, review the CompTIA Security+ SY0-701 Exam Dumps page. Each question includes a concise explanation of the correct answer and the technical reason the other choices are incorrect.

Question 1

What is a record of traffic decisions, sessions, rule matches, and related network-security events?

  1. Packet capture
  2. Metadata
  3. Firewall log
  4. Operating-system security log

Correct Answer: C

 

Correct Answer

Answer C is correct because Firewall log means a record of traffic decisions, sessions, rule matches, and related network-security events.

Incorrect Answers

Answer A is incorrect because Packet capture addresses a different requirement. Packet capture refers to recording of network packets for detailed protocol and content analysis.

Answer B is incorrect because Metadata represents a different security function. Metadata refers to descriptive information about other data, such as timestamps, source, destination, ownership, or file attributes.

Answer D is incorrect because Operating-system security log would fit a different scenario. Operating-system security log refers to an operating-system record of events such as authentication, privilege use, policy changes, and system activity.

 

Question 2

To reconstruct what happened inside a specific application, which security approach should be selected?

  1. Application log
  2. Vulnerability-scan result
  3. Security dashboard
  4. Operating-system security log

Correct Answer: A

 

Correct Answer

Answer A is correct because Application log means a record generated by an application describing requests, errors, authentication, transactions, or other program activity.

Incorrect Answers

Answer B is incorrect because Vulnerability-scan result addresses a different security requirement. Vulnerability-scan result refers to assessment output identifying suspected weaknesses, versions, and affected systems.

Answer C is incorrect because Security dashboard would fit a different scenario. Security dashboard refers to visual interface summarizing current metrics, alerts, or operational status.

Answer D is incorrect because Operating-system security log addresses a different requirement. Operating-system security log refers to an operating-system record of events such as authentication, privilege use, policy changes, and system activity.

 

Question 3

Which term describes telemetry from endpoint security tools or operating environments describing processes, files, users, and device events?

  1. Endpoint log
  2. IDS/IPS log
  3. Operating-system security log
  4. Firewall log

Correct Answer: A

 

Correct Answer

Answer A is correct because Endpoint log means telemetry from endpoint security tools or operating environments describing processes, files, users, and device events.

Incorrect Answers

Answer B is incorrect because IDS/IPS log represents a different security function. IDS/IPS log refers to a record of detection or prevention events produced by intrusion detection or prevention systems.

Answer C is incorrect because Operating-system security log addresses a different requirement. Operating-system security log refers to an operating-system record of events such as authentication, privilege use, policy changes, and system activity.

Answer D is incorrect because Firewall log would fit a different scenario. Firewall log refers to a record of traffic decisions, sessions, rule matches, and related network-security events.

 

Question 4

To trace identity and host security events, which security approach should be selected?

  1. Operating-system security log
  2. IDS/IPS log
  3. Endpoint log
  4. Vulnerability-scan result

Correct Answer: A

 

Correct Answer

Answer A is correct because Operating-system security log means an operating-system record of events such as authentication, privilege use, policy changes, and system activity.

Incorrect Answers

Answer B is incorrect because IDS/IPS log would fit a different scenario. IDS/IPS log refers to a record of detection or prevention events produced by intrusion detection or prevention systems.

Answer C is incorrect because Endpoint log addresses a different security requirement. Endpoint log refers to telemetry from endpoint security tools or operating environments describing processes, files, users, and device events.

Answer D is incorrect because Vulnerability-scan result addresses a different requirement. Vulnerability-scan result refers to assessment output identifying suspected weaknesses, versions, and affected systems.

 

Question 5

What is a record of detection or prevention events produced by intrusion detection or prevention systems?

  1. Network-device log
  2. Application log
  3. Vulnerability-scan result
  4. IDS/IPS log

Correct Answer: D

 

Correct Answer

Answer D is correct because IDS/IPS log means a record of detection or prevention events produced by intrusion detection or prevention systems.

Incorrect Answers

Answer A is incorrect because Network-device log represents a different security function. Network-device log refers to events from routers, switches, wireless controllers, or other network infrastructure.

Answer B is incorrect because Application log addresses a different requirement. Application log refers to a record generated by an application describing requests, errors, authentication, transactions, or other program activity.

Answer C is incorrect because Vulnerability-scan result would fit a different scenario. Vulnerability-scan result refers to assessment output identifying suspected weaknesses, versions, and affected systems.

 

Question 6

To investigate interface changes, routing events, authentication, and connectivity issues, which security approach should be selected?

  1. Packet capture
  2. Metadata
  3. Network-device log
  4. Application log

Correct Answer: C

 

Correct Answer

Answer C is correct because Network-device log means events from routers, switches, wireless controllers, or other network infrastructure.

Incorrect Answers

Answer A is incorrect because Packet capture addresses a different requirement. Packet capture refers to recording of network packets for detailed protocol and content analysis.

Answer B is incorrect because Metadata would fit a different scenario. Metadata refers to descriptive information about other data, such as timestamps, source, destination, ownership, or file attributes.

Answer D is incorrect because Application log addresses a different security requirement. Application log refers to a record generated by an application describing requests, errors, authentication, transactions, or other program activity.

 

Question 7

Which term describes descriptive information about other data, such as timestamps, source, destination, ownership, or file attributes?

  1. Metadata
  2. Vulnerability-scan result
  3. Application log
  4. Automated security report

Correct Answer: A

 

Correct Answer

Answer A is correct because Metadata means descriptive information about other data, such as timestamps, source, destination, ownership, or file attributes.

Incorrect Answers

Answer B is incorrect because Vulnerability-scan result would fit a different scenario. Vulnerability-scan result refers to assessment output identifying suspected weaknesses, versions, and affected systems.

Answer C is incorrect because Application log represents a different security function. Application log refers to a record generated by an application describing requests, errors, authentication, transactions, or other program activity.

Answer D is incorrect because Automated security report addresses a different requirement. Automated security report refers to machine-generated summary of findings, trends, or security-control results.

 

Question 8

To connect incident evidence with known exposures, which security approach should be selected?

  1. Firewall log
  2. Network-device log
  3. Application log
  4. Vulnerability-scan result

Correct Answer: D

 

Correct Answer

Answer D is correct because Vulnerability-scan result means assessment output identifying suspected weaknesses, versions, and affected systems.

Incorrect Answers

Answer A is incorrect because Firewall log would fit a different scenario. Firewall log refers to a record of traffic decisions, sessions, rule matches, and related network-security events.

Answer B is incorrect because Network-device log addresses a different security requirement. Network-device log refers to events from routers, switches, wireless controllers, or other network infrastructure.

Answer C is incorrect because Application log addresses a different requirement. Application log refers to a record generated by an application describing requests, errors, authentication, transactions, or other program activity.

 

Question 9

Which term describes machine-generated summary of findings, trends, or security-control results?

  1. Automated security report
  2. Vulnerability-scan result
  3. Firewall log
  4. Application log

Correct Answer: A

 

Correct Answer

Answer A is correct because Automated security report means machine-generated summary of findings, trends, or security-control results.

Incorrect Answers

Answer B is incorrect because Vulnerability-scan result would fit a different scenario. Vulnerability-scan result refers to assessment output identifying suspected weaknesses, versions, and affected systems.

Answer C is incorrect because Firewall log represents a different security function. Firewall log refers to a record of traffic decisions, sessions, rule matches, and related network-security events.

Answer D is incorrect because Application log addresses a different requirement. Application log refers to a record generated by an application describing requests, errors, authentication, transactions, or other program activity.

 

Question 10

To spot patterns and prioritize investigation across multiple data sources, which security approach should be selected?

  1. Endpoint log
  2. Security dashboard
  3. Operating-system security log
  4. Application log

Correct Answer: B

 

Correct Answer

Answer B is correct because Security dashboard means visual interface summarizing current metrics, alerts, or operational status.

Incorrect Answers

Answer A is incorrect because Endpoint log addresses a different security requirement. Endpoint log refers to telemetry from endpoint security tools or operating environments describing processes, files, users, and device events.

Answer C is incorrect because Operating-system security log would fit a different scenario. Operating-system security log refers to an operating-system record of events such as authentication, privilege use, policy changes, and system activity.

Answer D is incorrect because Application log addresses a different requirement. Application log refers to a record generated by an application describing requests, errors, authentication, transactions, or other program activity.

 

Question 11

Which term describes recording of network packets for detailed protocol and content analysis?

  1. Automated security report
  2. Operating-system security log
  3. Vulnerability-scan result
  4. Packet capture

Correct Answer: D

 

Correct Answer

Answer D is correct because Packet capture means recording of network packets for detailed protocol and content analysis.

Incorrect Answers

Answer A is incorrect because Automated security report would fit a different scenario. Automated security report refers to machine-generated summary of findings, trends, or security-control results.

Answer B is incorrect because Operating-system security log represents a different security function. Operating-system security log refers to an operating-system record of events such as authentication, privilege use, policy changes, and system activity.

Answer C is incorrect because Vulnerability-scan result addresses a different requirement. Vulnerability-scan result refers to assessment output identifying suspected weaknesses, versions, and affected systems.

 

Question 12

To determine which connections were allowed, denied, or inspected at a firewall, which security approach should be selected?

  1. Packet capture
  2. Metadata
  3. Firewall log
  4. IDS/IPS log

Correct Answer: C

 

Correct Answer

Answer C is correct because Firewall log means a record of traffic decisions, sessions, rule matches, and related network-security events.

Incorrect Answers

Answer A is incorrect because Packet capture represents a different security function. Packet capture refers to recording of network packets for detailed protocol and content analysis.

Answer B is incorrect because Metadata addresses a different requirement. Metadata refers to descriptive information about other data, such as timestamps, source, destination, ownership, or file attributes.

Answer D is incorrect because IDS/IPS log would fit a different scenario. IDS/IPS log refers to a record of detection or prevention events produced by intrusion detection or prevention systems.

 

Question 13

Which record is generated by an application describing requests, errors, authentication, transactions, or other program activity?

  1. Metadata
  2. IDS/IPS log
  3. Endpoint log
  4. Application log

Correct Answer: D

 

Correct Answer

Answer D is correct because Application log means a record generated by an application describing requests, errors, authentication, transactions, or other program activity.

Incorrect Answers

Answer A is incorrect because Metadata addresses a different requirement. Metadata refers to descriptive information about other data, such as timestamps, source, destination, ownership, or file attributes.

Answer B is incorrect because IDS/IPS log would fit a different scenario. IDS/IPS log refers to a record of detection or prevention events produced by intrusion detection or prevention systems.

Answer C is incorrect because Endpoint log addresses a different security requirement. Endpoint log refers to telemetry from endpoint security tools or operating environments describing processes, files, users, and device events.

 

Question 14

To investigate suspicious activity on a workstation or server, which security approach should be selected?

  1. Automated security report
  2. Network-device log
  3. Endpoint log
  4. Operating-system security log

Correct Answer: C

 

Correct Answer

Answer C is correct because Endpoint log means telemetry from endpoint security tools or operating environments describing processes, files, users, and device events.

Incorrect Answers

Answer A is incorrect because Automated security report addresses a different requirement. Automated security report refers to machine-generated summary of findings, trends, or security-control results.

Answer B is incorrect because Network-device log would fit a different scenario. Network-device log refers to events from routers, switches, wireless controllers, or other network infrastructure.

Answer D is incorrect because Operating-system security log represents a different security function. Operating-system security log refers to an operating-system record of events such as authentication, privilege use, policy changes, and system activity.

 

Question 15

What is an operating-system record of events such as authentication, privilege use, policy changes, and system activity?

  1. Endpoint log
  2. IDS/IPS log
  3. Operating-system security log
  4. Vulnerability-scan result

Correct Answer: C

 

Correct Answer

Answer C is correct because Operating-system security log means an operating-system record of events such as authentication, privilege use, policy changes, and system activity.

Incorrect Answers

Answer A is incorrect because Endpoint log addresses a different security requirement. Endpoint log refers to telemetry from endpoint security tools or operating environments describing processes, files, users, and device events.

Answer B is incorrect because IDS/IPS log addresses a different requirement. IDS/IPS log refers to a record of detection or prevention events produced by intrusion detection or prevention systems.

Answer D is incorrect because Vulnerability-scan result would fit a different scenario. Vulnerability-scan result refers to assessment output identifying suspected weaknesses, versions, and affected systems.

 

Question 16

To identify signatures, attack attempts, and enforcement actions, which security approach should be selected?

  1. IDS/IPS log
  2. Firewall log
  3. Vulnerability-scan result
  4. Security dashboard

Correct Answer: A

 

Correct Answer

Answer A is correct because IDS/IPS log means a record of detection or prevention events produced by intrusion detection or prevention systems.

Incorrect Answers

Answer B is incorrect because Firewall log would fit a different scenario. Firewall log refers to a record of traffic decisions, sessions, rule matches, and related network-security events.

Answer C is incorrect because Vulnerability-scan result addresses a different requirement. Vulnerability-scan result refers to assessment output identifying suspected weaknesses, versions, and affected systems.

Answer D is incorrect because Security dashboard represents a different security function. Security dashboard refers to visual interface summarizing current metrics, alerts, or operational status.

 

Question 17

Which term describes events from routers, switches, wireless controllers, or other network infrastructure?

  1. Firewall log
  2. Security dashboard
  3. Endpoint log
  4. Network-device log

Correct Answer: D

 

Correct Answer

Answer D is correct because Network-device log means events from routers, switches, wireless controllers, or other network infrastructure.

Incorrect Answers

Answer A is incorrect because Firewall log would fit a different scenario. Firewall log refers to a record of traffic decisions, sessions, rule matches, and related network-security events.

Answer B is incorrect because Security dashboard addresses a different security requirement. Security dashboard refers to visual interface summarizing current metrics, alerts, or operational status.

Answer C is incorrect because Endpoint log addresses a different requirement. Endpoint log refers to telemetry from endpoint security tools or operating environments describing processes, files, users, and device events.

 

Question 18

To correlate events and establish context without relying only on content, which security approach should be selected?

  1. Firewall log
  2. Metadata
  3. Packet capture
  4. Vulnerability-scan result

Correct Answer: B

 

Correct Answer

Answer B is correct because Metadata means descriptive information about other data, such as timestamps, source, destination, ownership, or file attributes.

Incorrect Answers

Answer A is incorrect because Firewall log addresses a different requirement. Firewall log refers to a record of traffic decisions, sessions, rule matches, and related network-security events.

Answer C is incorrect because Packet capture would fit a different scenario. Packet capture refers to recording of network packets for detailed protocol and content analysis.

Answer D is incorrect because Vulnerability-scan result represents a different security function. Vulnerability-scan result refers to assessment output identifying suspected weaknesses, versions, and affected systems.

 

Question 19

Which term describes assessment output identifying suspected weaknesses, versions, and affected systems?

  1. Metadata
  2. Vulnerability-scan result
  3. Application log
  4. Operating-system security log

Correct Answer: B

 

Correct Answer

Answer B is correct because Vulnerability-scan result means assessment output identifying suspected weaknesses, versions, and affected systems.

Incorrect Answers

Answer A is incorrect because Metadata addresses a different requirement. Metadata refers to descriptive information about other data, such as timestamps, source, destination, ownership, or file attributes.

Answer C is incorrect because Application log would fit a different scenario. Application log refers to a record generated by an application describing requests, errors, authentication, transactions, or other program activity.

Answer D is incorrect because Operating-system security log addresses a different security requirement. Operating-system security log refers to an operating-system record of events such as authentication, privilege use, policy changes, and system activity.

 

Question 20

To quickly review recurring security data in a standardized form, which security approach should be selected?

  1. Vulnerability-scan result
  2. Automated security report
  3. Packet capture
  4. Operating-system security log

Correct Answer: B

 

Correct Answer

Answer B is correct because Automated security report means machine-generated summary of findings, trends, or security-control results.

Incorrect Answers

Answer A is incorrect because Vulnerability-scan result represents a different security function. Vulnerability-scan result refers to assessment output identifying suspected weaknesses, versions, and affected systems.

Answer C is incorrect because Packet capture addresses a different requirement. Packet capture refers to recording of network packets for detailed protocol and content analysis.

Answer D is incorrect because Operating-system security log would fit a different scenario. Operating-system security log refers to an operating-system record of events such as authentication, privilege use, policy changes, and system activity.

 

Question 21

Which term describes visual interface summarizing current metrics, alerts, or operational status?

  1. Packet capture
  2. Operating-system security log
  3. Firewall log
  4. Security dashboard

Correct Answer: D

 

Correct Answer

Answer D is correct because Security dashboard means visual interface summarizing current metrics, alerts, or operational status.

Incorrect Answers

Answer A is incorrect because Packet capture would fit a different scenario. Packet capture refers to recording of network packets for detailed protocol and content analysis.

Answer B is incorrect because Operating-system security log addresses a different security requirement. Operating-system security log refers to an operating-system record of events such as authentication, privilege use, policy changes, and system activity.

Answer C is incorrect because Firewall log addresses a different requirement. Firewall log refers to a record of traffic decisions, sessions, rule matches, and related network-security events.

 

Question 22

To inspect communication at a granular level when flow summaries are insufficient, which security approach should be selected?

  1. Packet capture
  2. Application log
  3. Network-device log
  4. Endpoint log

Correct Answer: A

 

Correct Answer

Answer A is correct because Packet capture means recording of network packets for detailed protocol and content analysis.

Incorrect Answers

Answer B is incorrect because Application log would fit a different scenario. Application log refers to a record generated by an application describing requests, errors, authentication, transactions, or other program activity.

Answer C is incorrect because Network-device log represents a different security function. Network-device log refers to events from routers, switches, wireless controllers, or other network infrastructure.

Answer D is incorrect because Endpoint log addresses a different requirement. Endpoint log refers to telemetry from endpoint security tools or operating environments describing processes, files, users, and device events.

 

Question 23

An investigator needs evidence of which network connections matched allow or deny rules at a security boundary. Which log is the most direct source?

  1. Firewall log
  2. Endpoint log
  3. Network-device log
  4. Packet capture

Correct Answer: A

 

Correct Answer

Answer A is correct because Firewall log means a record of traffic decisions, sessions, rule matches, and related network-security events.

Incorrect Answers

Answer B is incorrect because Endpoint log represents a different security function. Endpoint log refers to telemetry from endpoint security tools or operating environments describing processes, files, users, and device events.

Answer C is incorrect because Network-device log addresses a different requirement. Network-device log refers to events from routers, switches, wireless controllers, or other network infrastructure.

Answer D is incorrect because Packet capture would fit a different scenario. Packet capture refers to recording of network packets for detailed protocol and content analysis.

 

Question 24

A transaction failed inside a particular application, and the investigator needs the application’s own execution events. Which log should be examined first?

  1. Automated security report
  2. Application log
  3. Endpoint log
  4. Operating-system security log

Correct Answer: B

 

Correct Answer

Answer B is correct because Application log means a record generated by an application describing requests, errors, authentication, transactions, or other program activity.

Incorrect Answers

Answer A is incorrect because Automated security report addresses a different security requirement. Automated security report refers to machine-generated summary of findings, trends, or security-control results.

Answer C is incorrect because Endpoint log addresses a different requirement. Endpoint log refers to telemetry from endpoint security tools or operating environments describing processes, files, users, and device events.

Answer D is incorrect because Operating-system security log would fit a different scenario. Operating-system security log refers to an operating-system record of events such as authentication, privilege use, policy changes, and system activity.

 

Question 25

A security analyst needs device-level evidence about processes, files and user activity collected by endpoint tooling. Which log category supplies this telemetry?

  1. Security dashboard
  2. Operating-system security log
  3. Endpoint log
  4. Metadata

Correct Answer: C

 

Correct Answer

Answer C is correct because Endpoint log means telemetry from endpoint security tools or operating environments describing processes, files, users, and device events.

Incorrect Answers

Answer A is incorrect because Security dashboard would fit a different scenario. Security dashboard refers to visual interface summarizing current metrics, alerts, or operational status.

Answer B is incorrect because Operating-system security log represents a different security function. Operating-system security log refers to an operating-system record of events such as authentication, privilege use, policy changes, and system activity.

Answer D is incorrect because Metadata addresses a different requirement. Metadata refers to descriptive information about other data, such as timestamps, source, destination, ownership, or file attributes.

 

Question 26

An investigation focuses on host authentication and operating-system security events. Which log is the most relevant starting point?

  1. Firewall log
  2. Application log
  3. Operating-system security log
  4. Metadata

Correct Answer: C

 

Correct Answer

Answer C is correct because Operating-system security log means an operating-system record of events such as authentication, privilege use, policy changes, and system activity.

Incorrect Answers

Answer A is incorrect because Firewall log addresses a different security requirement. Firewall log refers to a record of traffic decisions, sessions, rule matches, and related network-security events.

Answer B is incorrect because Application log addresses a different requirement. Application log refers to a record generated by an application describing requests, errors, authentication, transactions, or other program activity.

Answer D is incorrect because Metadata would fit a different scenario. Metadata refers to descriptive information about other data, such as timestamps, source, destination, ownership, or file attributes.

 

Question 27

An analyst needs the events explaining why an intrusion sensor generated an alert or blocked traffic. Which log records those detection or prevention actions?

  1. Vulnerability-scan result
  2. IDS/IPS log
  3. Application log
  4. Endpoint log

Correct Answer: B

 

Correct Answer

Answer B is correct because IDS/IPS log means a record of detection or prevention events produced by intrusion detection or prevention systems.

Incorrect Answers

Answer A is incorrect because Vulnerability-scan result would fit a different scenario. Vulnerability-scan result refers to assessment output identifying suspected weaknesses, versions, and affected systems.

Answer C is incorrect because Application log addresses a different requirement. Application log refers to a record generated by an application describing requests, errors, authentication, transactions, or other program activity.

Answer D is incorrect because Endpoint log represents a different security function. Endpoint log refers to telemetry from endpoint security tools or operating environments describing processes, files, users, and device events.

 

Question 28

A connectivity incident follows an interface change and routing updates on network equipment. Which log is most likely to record these device events?

  1. Automated security report
  2. Network-device log
  3. Packet capture
  4. Vulnerability-scan result

Correct Answer: B

 

Correct Answer

Answer B is correct because Network-device log means events from routers, switches, wireless controllers, or other network infrastructure.

Incorrect Answers

Answer A is incorrect because Automated security report addresses a different requirement. Automated security report refers to machine-generated summary of findings, trends, or security-control results.

Answer C is incorrect because Packet capture would fit a different scenario. Packet capture refers to recording of network packets for detailed protocol and content analysis.

Answer D is incorrect because Vulnerability-scan result addresses a different security requirement. Vulnerability-scan result refers to assessment output identifying suspected weaknesses, versions, and affected systems.

 

Question 29

An investigator reviews a file’s owner and timestamps without examining its contents. Which category of information is being inspected?

  1. Packet capture
  2. Metadata
  3. IDS/IPS log
  4. Application log

Correct Answer: B

 

Correct Answer

Answer B is correct because Metadata means descriptive information about other data, such as timestamps, source, destination, ownership, or file attributes.

Incorrect Answers

Answer A is incorrect because Packet capture addresses a different requirement. Packet capture refers to recording of network packets for detailed protocol and content analysis.

Answer C is incorrect because IDS/IPS log would fit a different scenario. IDS/IPS log refers to a record of detection or prevention events produced by intrusion detection or prevention systems.

Answer D is incorrect because Application log represents a different security function. Application log refers to a record generated by an application describing requests, errors, authentication, transactions, or other program activity.

 

Question 30

Incident evidence suggests exploitation of a known weakness. Which assessment output should the analyst consult to determine whether the affected system had that exposure?

  1. Security dashboard
  2. Operating-system security log
  3. Automated security report
  4. Vulnerability-scan result

Correct Answer: D

 

Correct Answer

Answer D is correct because Vulnerability-scan result means assessment output identifying suspected weaknesses, versions, and affected systems.

Incorrect Answers

Answer A is incorrect because Security dashboard addresses a different security requirement. Security dashboard refers to visual interface summarizing current metrics, alerts, or operational status.

Answer B is incorrect because Operating-system security log addresses a different requirement. Operating-system security log refers to an operating-system record of events such as authentication, privilege use, policy changes, and system activity.

Answer C is incorrect because Automated security report would fit a different scenario. Automated security report refers to machine-generated summary of findings, trends, or security-control results.

img