Courseiva
hardMultiple ChoiceObjective-mapped

220-1202 Practice Question: A security incident occurred where an…

A security incident occurred where an unauthorized user gained access to a workstation. The security team needs to review detailed logs of all user logon attempts, including successful and failed logins, for the past 48 hours. Which administrative tool and specific log should you access to provide this information?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Event Viewer > Windows Logs > Security

Event Viewer's Windows Logs > Security log records all security-related events, including logon attempts (success and failure). This is the standard location for auditing user activity. Other logs like System or Application do not focus on authentication events.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Event Viewer > Windows Logs > System

    Why it's wrong here

    The System log primarily captures events related to the operating system's core components, device drivers, and services, such as startup/shutdown events, hardware failures, or service status changes. It is not designed to track user-specific activities like logon or logoff attempts, which are considered security-related audit events. Therefore, an unauthorized user gaining access would not be logged here, making it an inappropriate source for this information.

  • Event Viewer > Windows Logs > Security

    Why this is correct

    The Security log is the designated repository for audit events on a Windows system, including successful and failed user logon attempts, account management operations, object access, and policy changes. To effectively track an unauthorized user gaining access, administrators would configure audit policies to record these specific security events, making this log crucial for forensic analysis and incident response. This log provides the detailed audit trail necessary to investigate security breaches.

  • Event Viewer > Applications and Services Logs > Microsoft > Windows > TerminalServices-LocalSessionManager

    Why it's wrong here

    This specific log within the Applications and Services Logs category is dedicated solely to events related to Remote Desktop Services (formerly Terminal Services) and local session management, such as the creation or termination of RDP sessions. While it tracks some session activity, it does not provide a comprehensive record of all local user logon attempts or general security audit events across the system. Its scope is too narrow and specialized to detect a broad unauthorized access incident not specifically tied to remote desktop.

  • Computer Management > System Tools > Shared Folders > Sessions

    Why it's wrong here

    The "Sessions" view under Shared Folders in Computer Management displays only currently active connections to shared resources on the local machine, showing who is connected and what files they have open. This tool provides real-time operational information but does not maintain a historical log of past logon events or unauthorized access attempts. It is a monitoring tool for active network shares, not an audit log for system security, and therefore would not contain records of a past unauthorized access.

About these practice questions

One of 495 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.