ExamOpsPractice free

CompTIA Security+ SY0-701 · Free study guide

Objective 4.9 — Use security data sources during investigations

No single data source tells the complete story. An investigator correlates evidence by timestamp, identity, host, address, process, session, and correlation identifier, while accounting for collection gaps and clock differences.

Firewall logs show allowed or denied network flows at an enforcement point. Application logs provide business and request context. Endpoint and operating-system logs show processes, files, services, authentication, and configuration. IDS/IPS records show matched traffic or behavior. Network device logs reveal changes and connections. Metadata can identify sender, recipient, time, type, and routing without containing full content.

Vulnerability logs and scan results explain known exposure, but a finding does not prove exploitation. Automated reports and dashboards summarize data and may hide detail or latency. Threat-intelligence feeds add reputation and context; age, source, confidence, and relevance matter.

NetFlow-style records summarize conversations. Packet captures contain detailed network frames and may expose sensitive content, so collection must be authorized, scoped, stored, and retained carefully. Encryption can limit payload visibility while connection metadata remains useful.

Build a defensible timeline

Normalize timestamps to a common reference and retain original values. Identify device clock drift and time-zone settings. Preserve raw evidence, record queries, and avoid overwriting source artifacts. A missing event can mean the action did not occur, the source did not log it, the record expired, or collection failed.

Suppose an identity alert shows an unusual login. Endpoint telemetry can reveal the device and process, application logs can show actions, firewall or network data can show destinations, and directory logs can show new permissions. Together they narrow scope. One geolocation mismatch alone may reflect a VPN or mobile carrier.

Choose the source closest to the question. For payload details, use authorized packet or application evidence; for process execution, use endpoint or OS data; for a permission change, use identity audit logs. Validate important conclusions with an independent source when practical.

Decision rule: correlate sources with clear provenance, recognize blind spots, and report only what the evidence supports.

Practice and apply this objective

A free ExamOps account includes guided hands-on labs plus 10 practice questions per day shared across live tracks, with a written explanation on every question. No card required.

Start practicing free