hardMultiple ChoiceObjective-mapped
220-1202 Practice Question: A security incident occurred where an…
A security incident occurred where an unauthorized user gained access to a workstation. The security team needs to review detailed logs of all user logon attempts, including successful and failed logins, for the past 48 hours. Which administrative tool and specific log should you access to provide this information?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Event Viewer > Windows Logs > Security
Event Viewer's Windows Logs > Security log records all security-related events, including logon attempts (success and failure). This is the standard location for auditing user activity. Other logs like System or Application do not focus on authentication events.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Event Viewer > Windows Logs > System
Why it's wrong here
The System log primarily captures events related to the operating system's core components, device drivers, and services, such as startup/shutdown events, hardware failures, or service status changes. It is not designed to track user-specific activities like logon or logoff attempts, which are considered security-related audit events. Therefore, an unauthorized user gaining access would not be logged here, making it an inappropriate source for this information.
- ✓
Event Viewer > Windows Logs > Security
Why this is correct
The Security log is the designated repository for audit events on a Windows system, including successful and failed user logon attempts, account management operations, object access, and policy changes. To effectively track an unauthorized user gaining access, administrators would configure audit policies to record these specific security events, making this log crucial for forensic analysis and incident response. This log provides the detailed audit trail necessary to investigate security breaches.
- ✗
Event Viewer > Applications and Services Logs > Microsoft > Windows > TerminalServices-LocalSessionManager
Why it's wrong here
This specific log within the Applications and Services Logs category is dedicated solely to events related to Remote Desktop Services (formerly Terminal Services) and local session management, such as the creation or termination of RDP sessions. While it tracks some session activity, it does not provide a comprehensive record of all local user logon attempts or general security audit events across the system. Its scope is too narrow and specialized to detect a broad unauthorized access incident not specifically tied to remote desktop.
- ✗
Computer Management > System Tools > Shared Folders > Sessions
Why it's wrong here
The "Sessions" view under Shared Folders in Computer Management displays only currently active connections to shared resources on the local machine, showing who is connected and what files they have open. This tool provides real-time operational information but does not maintain a historical log of past logon events or unauthorized access attempts. It is a monitoring tool for active network shares, not an audit log for system security, and therefore would not contain records of a past unauthorized access.
Go deeper
Related to this question
About these practice questions
One of 495 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.