Courseiva
Security Operations →easyMultiple Choice

CS0-003 Security Operations Practice Question

A security analyst is reviewing logs from multiple sources to investigate a potential intrusion. Which log source would provide the most reliable evidence of successful authentication from an unusual location?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Authentication logs

Authentication logs record login events including source IP, timestamp, and success/failure status, making them the best source for identifying successful authentication from unusual locations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Endpoint detection and response (EDR) logs

    Why it's wrong here

    Endpoint detection and response (EDR) logs are designed to monitor host-level activities, such as process creation, registry modifications, memory injections, and file system changes. While they are invaluable for identifying post-exploitation behavior and malware execution, they do not natively track centralized authentication events or directory service login attempts. Therefore, they are not the primary source for auditing user authentication success or failure across the network.

  • ✗

    Firewall logs

    Why it's wrong here

    Firewall logs record network-layer and transport-layer connection details, such as source and destination IP addresses, port numbers, and protocol types, along with action states like permit or deny. They lack the application-layer visibility required to parse and log the specific success or failure outcomes of user authentication handshakes. Consequently, they cannot verify whether a login attempt succeeded or failed.

  • ✓

    Authentication logs

    Why this is correct

    Authentication logs, such as those generated by Active Directory, Kerberos, or RADIUS servers, explicitly record identity verification events, including usernames, source IPs, timestamps, and explicit success or failure codes. These logs are the definitive source for tracking credential usage, identifying brute-force attacks, and verifying successful access to systems. Analyzing these events allows security analysts to correlate login patterns with potential unauthorized access.

  • ✗

    DNS logs

    Why it's wrong here

    Domain Name System (DNS) logs capture queries and responses mapping hostnames to IP addresses, which helps identify command-and-control (C2) traffic or domain generation algorithms. They do not contain any user credential data, session negotiation details, or authentication status information. As a result, DNS logs are entirely unsuitable for auditing user login attempts or verifying authentication outcomes.

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.