Security+ Exam Tip: Match the Right Log Source to What It Can Actually See
The Security Operations domain makes up 28% of the CompTIA Security+ SY0-701 exam, with many scenario questions requiring candidates to identify which log source could detect a specific event. Each log type has a distinct vantage point: firewall logs record connections but not payload content, endpoint logs capture process and account activity, and network flow logs reveal traffic volume without inspecting data. IDS/IPS logs confirm a signature match but do not clarify whether an attack succeeded, while packet captures are comprehensive but only useful if recording was enabled before the incident. A common exam mistake is selecting the most data-rich source rather than the one correctly positioned to observe the event in question. Treating the absence of log entries as proof nothing occurred is another pitfall, since unmonitored hosts generate no events regardless of compromise.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in