easyMultiple Choice
200-201 Practice Question: An analyst needs to review the Windows event logs…
An analyst needs to review the Windows event logs from a host to determine if a user's account was used to log in at an unusual time. Which log type should the analyst check?
⚠ Common exam trap
Cisco often tests the distinction between the Security log (which records authentication events) and the System log (which records system-level events), leading candidates to mistakenly choose the System log for logon analysis.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Security
The Security log in Windows Event Viewer records audit events, including successful and failed logon attempts (Event ID 4624 for successful logons). This log type is the correct source for determining if a user's account was used to log in at an unusual time, as it captures the timestamp and details of each authentication event.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Application
Why it's wrong here
The Application log records events from installed applications and services, not authentication activity, so it holds no logon timestamps. It is the right place for application crashes or service errors. Account logon times appear in the Security log, making this the wrong choice for the analyst's question.
- ✗
System
Why it's wrong here
The System log records kernel, driver and operating-system component events such as service start failures, not user authentication. It is the correct source for hardware or boot problems. Logon activity, including unusual times, is recorded in the Security log, so this option fails the scenario.
- ✗
Setup
Why it's wrong here
The Setup log records installation, update and role-configuration events during Windows servicing operations, not interactive or network logons. It is useful for troubleshooting failed updates. Authentication events, including logon times, are written to the Security log, so this option cannot answer the analyst's question.
- ✓
Security
Why this is correct
Successful and failed logon events, including timestamps and account names, are recorded in the Security log, so it is the only log type that reveals whether an account was used to authenticate at an unusual time.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.