CS0-003 Security Operations Practice Question
A security analyst is reviewing logs from multiple sources to investigate a potential intrusion. Which log source would provide the most reliable evidence of successful authentication from an unusual location?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Authentication logs
Authentication logs record login events including source IP, timestamp, and success/failure status, making them the best source for identifying successful authentication from unusual locations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Endpoint detection and response (EDR) logs
Why it's wrong here
Endpoint detection and response (EDR) logs are designed to monitor host-level activities, such as process creation, registry modifications, memory injections, and file system changes. While they are invaluable for identifying post-exploitation behavior and malware execution, they do not natively track centralized authentication events or directory service login attempts. Therefore, they are not the primary source for auditing user authentication success or failure across the network.
- ✗
Firewall logs
Why it's wrong here
Firewall logs record network-layer and transport-layer connection details, such as source and destination IP addresses, port numbers, and protocol types, along with action states like permit or deny. They lack the application-layer visibility required to parse and log the specific success or failure outcomes of user authentication handshakes. Consequently, they cannot verify whether a login attempt succeeded or failed.
- ✓
Authentication logs
Why this is correct
Authentication logs, such as those generated by Active Directory, Kerberos, or RADIUS servers, explicitly record identity verification events, including usernames, source IPs, timestamps, and explicit success or failure codes. These logs are the definitive source for tracking credential usage, identifying brute-force attacks, and verifying successful access to systems. Analyzing these events allows security analysts to correlate login patterns with potential unauthorized access.
- ✗
DNS logs
Why it's wrong here
Domain Name System (DNS) logs capture queries and responses mapping hostnames to IP addresses, which helps identify command-and-control (C2) traffic or domain generation algorithms. They do not contain any user credential data, session negotiation details, or authentication status information. As a result, DNS logs are entirely unsuitable for auditing user login attempts or verifying authentication outcomes.
Go deeper
Related to this question
Learn chapter
Critical Windows Event IDs for Security
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Log source
A log source is any system, device, or application that generates and records event data, such as timestamps and activities, for monitoring and security analysis.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.