Courseiva
hardMultiple Choice

220-1202 Practice Question: A security incident occurred on a Windows 10…

A security incident occurred on a Windows 10 workstation, and you need to review detailed logs of user logon attempts, including successful and failed logins, to identify unauthorized access. Which tool should you use to view these security logs?

⚠ Common exam trap

The A+ exam often tests the distinction between tools that view logs (Event Viewer) versus tools that configure settings (Group Policy Editor) or monitor performance (Performance Monitor), leading candidates to confuse administrative utilities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Event Viewer

Event Viewer is the correct tool because it provides access to Windows Security logs, which record detailed information about user logon attempts, including both successful (Event ID 4624) and failed (Event ID 4625) logins. These logs are essential for forensic analysis of unauthorized access on a Windows 10 workstation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Reliability Monitor

    Why it's wrong here

    Reliability Monitor tracks system stability, application crashes and driver failures over time via Reliability Analysis Component data; it records no logon audit events. It would be tempting when investigating a workstation that crashed or degraded, but authentication records require Event Viewer's Security log with logon auditing enabled.

  • ✗

    Performance Monitor

    Why it's wrong here

    Performance Monitor collects real-time and logged counter data such as CPU, memory and disk throughput; it does not read the Security event log. It would be tempting when diagnosing resource exhaustion during an incident, where counters are the right tool, but logon success and failure records live in Event Viewer.

  • ✓

    Event Viewer

    Why this is correct

    Event Viewer's Security log records Windows logon events, including audit success and failure entries with account names, timestamps and logon types. Reviewing event IDs 4624 and 4625 satisfies the requirement to identify both successful and failed logon attempts during the incident investigation.

  • ✗

    Group Policy Editor

    Why it's wrong here

    Group Policy Editor configures policy settings such as audit policy and security options; it does not display recorded events. It would be tempting because audit policy determines which logon events get logged, but reviewing the resulting entries requires Event Viewer's Security log. Group Policy Editor is the configuration tool, not the viewer.

About these practice questions

One of 687 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.