hardMultiple Choice
220-1202 Practice Question: A security incident occurred where an…
A security incident occurred where an unauthorized user gained access to a workstation. The security team needs to review detailed logs of all user logon attempts, including successful and failed logins, for the past 48 hours. Which administrative tool and specific log should you access to provide this information?
⚠ Common exam trap
220-1202 often tests whether candidates know which Event Viewer log holds authentication data — many pick the System log or a service-specific log, missing that only the Security log contains 4624/4625 events.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Event Viewer > Windows Logs > Security
Windows records all authentication events — successful and failed logons, logoffs, and account changes — in the Security log, accessible via Event Viewer under Windows Logs > Security. Key event IDs include 4624 (successful logon), 4625 (failed logon), 4634 (logoff), and 4648 (logon using explicit credentials). Reviewing this log for the past 48 hours gives the analyst the complete authentication timeline needed for the incident investigation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Event Viewer > Windows Logs > System
Why it's wrong here
The System log primarily captures events related to the operating system's core components, device drivers, and services, such as startup/shutdown events, hardware failures, or service status changes. It is not designed to track user-specific activities like logon or logoff attempts, which are considered security-related audit events. Therefore, an unauthorized user gaining access would not be logged here, making it an inappropriate source for this information.
- ✓
Event Viewer > Windows Logs > Security
Why this is correct
The Security log is the designated repository for audit events on a Windows system, including successful and failed user logon attempts, account management operations, object access, and policy changes. To effectively track an unauthorized user gaining access, administrators would configure audit policies to record these specific security events, making this log crucial for forensic analysis and incident response. This log provides the detailed audit trail necessary to investigate security breaches.
- ✗
Event Viewer > Applications and Services Logs > Microsoft > Windows > TerminalServices-LocalSessionManager
Why it's wrong here
This specific log within the Applications and Services Logs category is dedicated solely to events related to Remote Desktop Services (formerly Terminal Services) and local session management, such as the creation or termination of RDP sessions. While it tracks some session activity, it does not provide a comprehensive record of all local user logon attempts or general security audit events across the system. Its scope is too narrow and specialized to detect a broad unauthorized access incident not specifically tied to remote desktop.
- ✗
Computer Management > System Tools > Shared Folders > Sessions
Why it's wrong here
The "Sessions" view under Shared Folders in Computer Management displays only currently active connections to shared resources on the local machine, showing who is connected and what files they have open. This tool provides real-time operational information but does not maintain a historical log of past logon events or unauthorized access attempts. It is a monitoring tool for active network shares, not an audit log for system security, and therefore would not contain records of a past unauthorized access.
Go deeper
Related to this question
About these practice questions
One of 687 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.