CompTIA Security+ SY0-701 Investigation Data Sources Practice Test
Topic 22 focuses on Investigation Data Sources for the CompTIA Security+ certification and the SY0-701 exam, using practical cybersecurity scenarios aligned to the published Security+ objectives. For broader exam preparation, review the CompTIA Security+ SY0-701 Exam Dumps page. Each question includes a concise explanation of the correct answer and the technical reason the other choices are incorrect.
Question 1
What is a record of traffic decisions, sessions, rule matches, and related network-security events?
Correct Answer: C
Correct Answer
Answer C is correct because Firewall log means a record of traffic decisions, sessions, rule matches, and related network-security events.
Incorrect Answers
Answer A is incorrect because Packet capture addresses a different requirement. Packet capture refers to recording of network packets for detailed protocol and content analysis.
Answer B is incorrect because Metadata represents a different security function. Metadata refers to descriptive information about other data, such as timestamps, source, destination, ownership, or file attributes.
Answer D is incorrect because Operating-system security log would fit a different scenario. Operating-system security log refers to an operating-system record of events such as authentication, privilege use, policy changes, and system activity.
Question 2
To reconstruct what happened inside a specific application, which security approach should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because Application log means a record generated by an application describing requests, errors, authentication, transactions, or other program activity.
Incorrect Answers
Answer B is incorrect because Vulnerability-scan result addresses a different security requirement. Vulnerability-scan result refers to assessment output identifying suspected weaknesses, versions, and affected systems.
Answer C is incorrect because Security dashboard would fit a different scenario. Security dashboard refers to visual interface summarizing current metrics, alerts, or operational status.
Answer D is incorrect because Operating-system security log addresses a different requirement. Operating-system security log refers to an operating-system record of events such as authentication, privilege use, policy changes, and system activity.
Question 3
Which term describes telemetry from endpoint security tools or operating environments describing processes, files, users, and device events?
Correct Answer: A
Correct Answer
Answer A is correct because Endpoint log means telemetry from endpoint security tools or operating environments describing processes, files, users, and device events.
Incorrect Answers
Answer B is incorrect because IDS/IPS log represents a different security function. IDS/IPS log refers to a record of detection or prevention events produced by intrusion detection or prevention systems.
Answer C is incorrect because Operating-system security log addresses a different requirement. Operating-system security log refers to an operating-system record of events such as authentication, privilege use, policy changes, and system activity.
Answer D is incorrect because Firewall log would fit a different scenario. Firewall log refers to a record of traffic decisions, sessions, rule matches, and related network-security events.
Question 4
To trace identity and host security events, which security approach should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because Operating-system security log means an operating-system record of events such as authentication, privilege use, policy changes, and system activity.
Incorrect Answers
Answer B is incorrect because IDS/IPS log would fit a different scenario. IDS/IPS log refers to a record of detection or prevention events produced by intrusion detection or prevention systems.
Answer C is incorrect because Endpoint log addresses a different security requirement. Endpoint log refers to telemetry from endpoint security tools or operating environments describing processes, files, users, and device events.
Answer D is incorrect because Vulnerability-scan result addresses a different requirement. Vulnerability-scan result refers to assessment output identifying suspected weaknesses, versions, and affected systems.
Question 5
What is a record of detection or prevention events produced by intrusion detection or prevention systems?
Correct Answer: D
Correct Answer
Answer D is correct because IDS/IPS log means a record of detection or prevention events produced by intrusion detection or prevention systems.
Incorrect Answers
Answer A is incorrect because Network-device log represents a different security function. Network-device log refers to events from routers, switches, wireless controllers, or other network infrastructure.
Answer B is incorrect because Application log addresses a different requirement. Application log refers to a record generated by an application describing requests, errors, authentication, transactions, or other program activity.
Answer C is incorrect because Vulnerability-scan result would fit a different scenario. Vulnerability-scan result refers to assessment output identifying suspected weaknesses, versions, and affected systems.
Question 6
To investigate interface changes, routing events, authentication, and connectivity issues, which security approach should be selected?
Correct Answer: C
Correct Answer
Answer C is correct because Network-device log means events from routers, switches, wireless controllers, or other network infrastructure.
Incorrect Answers
Answer A is incorrect because Packet capture addresses a different requirement. Packet capture refers to recording of network packets for detailed protocol and content analysis.
Answer B is incorrect because Metadata would fit a different scenario. Metadata refers to descriptive information about other data, such as timestamps, source, destination, ownership, or file attributes.
Answer D is incorrect because Application log addresses a different security requirement. Application log refers to a record generated by an application describing requests, errors, authentication, transactions, or other program activity.
Question 7
Which term describes descriptive information about other data, such as timestamps, source, destination, ownership, or file attributes?
Correct Answer: A
Correct Answer
Answer A is correct because Metadata means descriptive information about other data, such as timestamps, source, destination, ownership, or file attributes.
Incorrect Answers
Answer B is incorrect because Vulnerability-scan result would fit a different scenario. Vulnerability-scan result refers to assessment output identifying suspected weaknesses, versions, and affected systems.
Answer C is incorrect because Application log represents a different security function. Application log refers to a record generated by an application describing requests, errors, authentication, transactions, or other program activity.
Answer D is incorrect because Automated security report addresses a different requirement. Automated security report refers to machine-generated summary of findings, trends, or security-control results.
Question 8
To connect incident evidence with known exposures, which security approach should be selected?
Correct Answer: D
Correct Answer
Answer D is correct because Vulnerability-scan result means assessment output identifying suspected weaknesses, versions, and affected systems.
Incorrect Answers
Answer A is incorrect because Firewall log would fit a different scenario. Firewall log refers to a record of traffic decisions, sessions, rule matches, and related network-security events.
Answer B is incorrect because Network-device log addresses a different security requirement. Network-device log refers to events from routers, switches, wireless controllers, or other network infrastructure.
Answer C is incorrect because Application log addresses a different requirement. Application log refers to a record generated by an application describing requests, errors, authentication, transactions, or other program activity.
Question 9
Which term describes machine-generated summary of findings, trends, or security-control results?
Correct Answer: A
Correct Answer
Answer A is correct because Automated security report means machine-generated summary of findings, trends, or security-control results.
Incorrect Answers
Answer B is incorrect because Vulnerability-scan result would fit a different scenario. Vulnerability-scan result refers to assessment output identifying suspected weaknesses, versions, and affected systems.
Answer C is incorrect because Firewall log represents a different security function. Firewall log refers to a record of traffic decisions, sessions, rule matches, and related network-security events.
Answer D is incorrect because Application log addresses a different requirement. Application log refers to a record generated by an application describing requests, errors, authentication, transactions, or other program activity.
Question 10
To spot patterns and prioritize investigation across multiple data sources, which security approach should be selected?
Correct Answer: B
Correct Answer
Answer B is correct because Security dashboard means visual interface summarizing current metrics, alerts, or operational status.
Incorrect Answers
Answer A is incorrect because Endpoint log addresses a different security requirement. Endpoint log refers to telemetry from endpoint security tools or operating environments describing processes, files, users, and device events.
Answer C is incorrect because Operating-system security log would fit a different scenario. Operating-system security log refers to an operating-system record of events such as authentication, privilege use, policy changes, and system activity.
Answer D is incorrect because Application log addresses a different requirement. Application log refers to a record generated by an application describing requests, errors, authentication, transactions, or other program activity.
Question 11
Which term describes recording of network packets for detailed protocol and content analysis?
Correct Answer: D
Correct Answer
Answer D is correct because Packet capture means recording of network packets for detailed protocol and content analysis.
Incorrect Answers
Answer A is incorrect because Automated security report would fit a different scenario. Automated security report refers to machine-generated summary of findings, trends, or security-control results.
Answer B is incorrect because Operating-system security log represents a different security function. Operating-system security log refers to an operating-system record of events such as authentication, privilege use, policy changes, and system activity.
Answer C is incorrect because Vulnerability-scan result addresses a different requirement. Vulnerability-scan result refers to assessment output identifying suspected weaknesses, versions, and affected systems.
Question 12
To determine which connections were allowed, denied, or inspected at a firewall, which security approach should be selected?
Correct Answer: C
Correct Answer
Answer C is correct because Firewall log means a record of traffic decisions, sessions, rule matches, and related network-security events.
Incorrect Answers
Answer A is incorrect because Packet capture represents a different security function. Packet capture refers to recording of network packets for detailed protocol and content analysis.
Answer B is incorrect because Metadata addresses a different requirement. Metadata refers to descriptive information about other data, such as timestamps, source, destination, ownership, or file attributes.
Answer D is incorrect because IDS/IPS log would fit a different scenario. IDS/IPS log refers to a record of detection or prevention events produced by intrusion detection or prevention systems.
Question 13
Which record is generated by an application describing requests, errors, authentication, transactions, or other program activity?
Correct Answer: D
Correct Answer
Answer D is correct because Application log means a record generated by an application describing requests, errors, authentication, transactions, or other program activity.
Incorrect Answers
Answer A is incorrect because Metadata addresses a different requirement. Metadata refers to descriptive information about other data, such as timestamps, source, destination, ownership, or file attributes.
Answer B is incorrect because IDS/IPS log would fit a different scenario. IDS/IPS log refers to a record of detection or prevention events produced by intrusion detection or prevention systems.
Answer C is incorrect because Endpoint log addresses a different security requirement. Endpoint log refers to telemetry from endpoint security tools or operating environments describing processes, files, users, and device events.
Question 14
To investigate suspicious activity on a workstation or server, which security approach should be selected?
Correct Answer: C
Correct Answer
Answer C is correct because Endpoint log means telemetry from endpoint security tools or operating environments describing processes, files, users, and device events.
Incorrect Answers
Answer A is incorrect because Automated security report addresses a different requirement. Automated security report refers to machine-generated summary of findings, trends, or security-control results.
Answer B is incorrect because Network-device log would fit a different scenario. Network-device log refers to events from routers, switches, wireless controllers, or other network infrastructure.
Answer D is incorrect because Operating-system security log represents a different security function. Operating-system security log refers to an operating-system record of events such as authentication, privilege use, policy changes, and system activity.
Question 15
What is an operating-system record of events such as authentication, privilege use, policy changes, and system activity?
Correct Answer: C
Correct Answer
Answer C is correct because Operating-system security log means an operating-system record of events such as authentication, privilege use, policy changes, and system activity.
Incorrect Answers
Answer A is incorrect because Endpoint log addresses a different security requirement. Endpoint log refers to telemetry from endpoint security tools or operating environments describing processes, files, users, and device events.
Answer B is incorrect because IDS/IPS log addresses a different requirement. IDS/IPS log refers to a record of detection or prevention events produced by intrusion detection or prevention systems.
Answer D is incorrect because Vulnerability-scan result would fit a different scenario. Vulnerability-scan result refers to assessment output identifying suspected weaknesses, versions, and affected systems.
Question 16
To identify signatures, attack attempts, and enforcement actions, which security approach should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because IDS/IPS log means a record of detection or prevention events produced by intrusion detection or prevention systems.
Incorrect Answers
Answer B is incorrect because Firewall log would fit a different scenario. Firewall log refers to a record of traffic decisions, sessions, rule matches, and related network-security events.
Answer C is incorrect because Vulnerability-scan result addresses a different requirement. Vulnerability-scan result refers to assessment output identifying suspected weaknesses, versions, and affected systems.
Answer D is incorrect because Security dashboard represents a different security function. Security dashboard refers to visual interface summarizing current metrics, alerts, or operational status.
Question 17
Which term describes events from routers, switches, wireless controllers, or other network infrastructure?
Correct Answer: D
Correct Answer
Answer D is correct because Network-device log means events from routers, switches, wireless controllers, or other network infrastructure.
Incorrect Answers
Answer A is incorrect because Firewall log would fit a different scenario. Firewall log refers to a record of traffic decisions, sessions, rule matches, and related network-security events.
Answer B is incorrect because Security dashboard addresses a different security requirement. Security dashboard refers to visual interface summarizing current metrics, alerts, or operational status.
Answer C is incorrect because Endpoint log addresses a different requirement. Endpoint log refers to telemetry from endpoint security tools or operating environments describing processes, files, users, and device events.
Question 18
To correlate events and establish context without relying only on content, which security approach should be selected?
Correct Answer: B
Correct Answer
Answer B is correct because Metadata means descriptive information about other data, such as timestamps, source, destination, ownership, or file attributes.
Incorrect Answers
Answer A is incorrect because Firewall log addresses a different requirement. Firewall log refers to a record of traffic decisions, sessions, rule matches, and related network-security events.
Answer C is incorrect because Packet capture would fit a different scenario. Packet capture refers to recording of network packets for detailed protocol and content analysis.
Answer D is incorrect because Vulnerability-scan result represents a different security function. Vulnerability-scan result refers to assessment output identifying suspected weaknesses, versions, and affected systems.
Question 19
Which term describes assessment output identifying suspected weaknesses, versions, and affected systems?
Correct Answer: B
Correct Answer
Answer B is correct because Vulnerability-scan result means assessment output identifying suspected weaknesses, versions, and affected systems.
Incorrect Answers
Answer A is incorrect because Metadata addresses a different requirement. Metadata refers to descriptive information about other data, such as timestamps, source, destination, ownership, or file attributes.
Answer C is incorrect because Application log would fit a different scenario. Application log refers to a record generated by an application describing requests, errors, authentication, transactions, or other program activity.
Answer D is incorrect because Operating-system security log addresses a different security requirement. Operating-system security log refers to an operating-system record of events such as authentication, privilege use, policy changes, and system activity.
Question 20
To quickly review recurring security data in a standardized form, which security approach should be selected?
Correct Answer: B
Correct Answer
Answer B is correct because Automated security report means machine-generated summary of findings, trends, or security-control results.
Incorrect Answers
Answer A is incorrect because Vulnerability-scan result represents a different security function. Vulnerability-scan result refers to assessment output identifying suspected weaknesses, versions, and affected systems.
Answer C is incorrect because Packet capture addresses a different requirement. Packet capture refers to recording of network packets for detailed protocol and content analysis.
Answer D is incorrect because Operating-system security log would fit a different scenario. Operating-system security log refers to an operating-system record of events such as authentication, privilege use, policy changes, and system activity.
Question 21
Which term describes visual interface summarizing current metrics, alerts, or operational status?
Correct Answer: D
Correct Answer
Answer D is correct because Security dashboard means visual interface summarizing current metrics, alerts, or operational status.
Incorrect Answers
Answer A is incorrect because Packet capture would fit a different scenario. Packet capture refers to recording of network packets for detailed protocol and content analysis.
Answer B is incorrect because Operating-system security log addresses a different security requirement. Operating-system security log refers to an operating-system record of events such as authentication, privilege use, policy changes, and system activity.
Answer C is incorrect because Firewall log addresses a different requirement. Firewall log refers to a record of traffic decisions, sessions, rule matches, and related network-security events.
Question 22
To inspect communication at a granular level when flow summaries are insufficient, which security approach should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because Packet capture means recording of network packets for detailed protocol and content analysis.
Incorrect Answers
Answer B is incorrect because Application log would fit a different scenario. Application log refers to a record generated by an application describing requests, errors, authentication, transactions, or other program activity.
Answer C is incorrect because Network-device log represents a different security function. Network-device log refers to events from routers, switches, wireless controllers, or other network infrastructure.
Answer D is incorrect because Endpoint log addresses a different requirement. Endpoint log refers to telemetry from endpoint security tools or operating environments describing processes, files, users, and device events.
Question 23
An investigator needs evidence of which network connections matched allow or deny rules at a security boundary. Which log is the most direct source?
Correct Answer: A
Correct Answer
Answer A is correct because Firewall log means a record of traffic decisions, sessions, rule matches, and related network-security events.
Incorrect Answers
Answer B is incorrect because Endpoint log represents a different security function. Endpoint log refers to telemetry from endpoint security tools or operating environments describing processes, files, users, and device events.
Answer C is incorrect because Network-device log addresses a different requirement. Network-device log refers to events from routers, switches, wireless controllers, or other network infrastructure.
Answer D is incorrect because Packet capture would fit a different scenario. Packet capture refers to recording of network packets for detailed protocol and content analysis.
Question 24
A transaction failed inside a particular application, and the investigator needs the application’s own execution events. Which log should be examined first?
Correct Answer: B
Correct Answer
Answer B is correct because Application log means a record generated by an application describing requests, errors, authentication, transactions, or other program activity.
Incorrect Answers
Answer A is incorrect because Automated security report addresses a different security requirement. Automated security report refers to machine-generated summary of findings, trends, or security-control results.
Answer C is incorrect because Endpoint log addresses a different requirement. Endpoint log refers to telemetry from endpoint security tools or operating environments describing processes, files, users, and device events.
Answer D is incorrect because Operating-system security log would fit a different scenario. Operating-system security log refers to an operating-system record of events such as authentication, privilege use, policy changes, and system activity.
Question 25
A security analyst needs device-level evidence about processes, files and user activity collected by endpoint tooling. Which log category supplies this telemetry?
Correct Answer: C
Correct Answer
Answer C is correct because Endpoint log means telemetry from endpoint security tools or operating environments describing processes, files, users, and device events.
Incorrect Answers
Answer A is incorrect because Security dashboard would fit a different scenario. Security dashboard refers to visual interface summarizing current metrics, alerts, or operational status.
Answer B is incorrect because Operating-system security log represents a different security function. Operating-system security log refers to an operating-system record of events such as authentication, privilege use, policy changes, and system activity.
Answer D is incorrect because Metadata addresses a different requirement. Metadata refers to descriptive information about other data, such as timestamps, source, destination, ownership, or file attributes.
Question 26
An investigation focuses on host authentication and operating-system security events. Which log is the most relevant starting point?
Correct Answer: C
Correct Answer
Answer C is correct because Operating-system security log means an operating-system record of events such as authentication, privilege use, policy changes, and system activity.
Incorrect Answers
Answer A is incorrect because Firewall log addresses a different security requirement. Firewall log refers to a record of traffic decisions, sessions, rule matches, and related network-security events.
Answer B is incorrect because Application log addresses a different requirement. Application log refers to a record generated by an application describing requests, errors, authentication, transactions, or other program activity.
Answer D is incorrect because Metadata would fit a different scenario. Metadata refers to descriptive information about other data, such as timestamps, source, destination, ownership, or file attributes.
Question 27
An analyst needs the events explaining why an intrusion sensor generated an alert or blocked traffic. Which log records those detection or prevention actions?
Correct Answer: B
Correct Answer
Answer B is correct because IDS/IPS log means a record of detection or prevention events produced by intrusion detection or prevention systems.
Incorrect Answers
Answer A is incorrect because Vulnerability-scan result would fit a different scenario. Vulnerability-scan result refers to assessment output identifying suspected weaknesses, versions, and affected systems.
Answer C is incorrect because Application log addresses a different requirement. Application log refers to a record generated by an application describing requests, errors, authentication, transactions, or other program activity.
Answer D is incorrect because Endpoint log represents a different security function. Endpoint log refers to telemetry from endpoint security tools or operating environments describing processes, files, users, and device events.
Question 28
A connectivity incident follows an interface change and routing updates on network equipment. Which log is most likely to record these device events?
Correct Answer: B
Correct Answer
Answer B is correct because Network-device log means events from routers, switches, wireless controllers, or other network infrastructure.
Incorrect Answers
Answer A is incorrect because Automated security report addresses a different requirement. Automated security report refers to machine-generated summary of findings, trends, or security-control results.
Answer C is incorrect because Packet capture would fit a different scenario. Packet capture refers to recording of network packets for detailed protocol and content analysis.
Answer D is incorrect because Vulnerability-scan result addresses a different security requirement. Vulnerability-scan result refers to assessment output identifying suspected weaknesses, versions, and affected systems.
Question 29
An investigator reviews a file’s owner and timestamps without examining its contents. Which category of information is being inspected?
Correct Answer: B
Correct Answer
Answer B is correct because Metadata means descriptive information about other data, such as timestamps, source, destination, ownership, or file attributes.
Incorrect Answers
Answer A is incorrect because Packet capture addresses a different requirement. Packet capture refers to recording of network packets for detailed protocol and content analysis.
Answer C is incorrect because IDS/IPS log would fit a different scenario. IDS/IPS log refers to a record of detection or prevention events produced by intrusion detection or prevention systems.
Answer D is incorrect because Application log represents a different security function. Application log refers to a record generated by an application describing requests, errors, authentication, transactions, or other program activity.
Question 30
Incident evidence suggests exploitation of a known weakness. Which assessment output should the analyst consult to determine whether the affected system had that exposure?
Correct Answer: D
Correct Answer
Answer D is correct because Vulnerability-scan result means assessment output identifying suspected weaknesses, versions, and affected systems.
Incorrect Answers
Answer A is incorrect because Security dashboard addresses a different security requirement. Security dashboard refers to visual interface summarizing current metrics, alerts, or operational status.
Answer B is incorrect because Operating-system security log addresses a different requirement. Operating-system security log refers to an operating-system record of events such as authentication, privilege use, policy changes, and system activity.
Answer C is incorrect because Automated security report would fit a different scenario. Automated security report refers to machine-generated summary of findings, trends, or security-control results.
Popular posts
Recent Posts
