Courseiva
Security OperationsmediumMultiple ChoiceObjective-mapped

SY0-701 Security Operations Practice Question

A privileged account is used on a jump box at 02:15, and the SIEM shows multiple interactive logons from the same account to different servers within 10 minutes. The administrator says they used a password vault for the session. Which log source best confirms whether the access was authorized?

⚠ Common exam trap

Test-takers frequently assume DHCP logs or generic server logs can validate authentication authorization, when in fact only the PAM audit trail provides the cryptographic proof of vault-mediated access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Privileged access management or password vault audit logs

The privileged access management (PAM) or password vault audit logs are the definitive source because they record exactly when a password was checked out, which user performed the checkout, and the specific session ID or ticket associated with the jump box use. Since the administrator claims the password vault was used, these logs will show the checkout event at 02:15 and the subsequent interactive logons, confirming whether the vault authorized the session. No other log source can tie the authentication to the vault's approval process.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Privileged access management or password vault audit logs

    Why this is correct

    Privileged access management (PAM) or password vault audit logs are the definitive source for validating the legitimacy of a privileged session initiated from a jump box. These logs record the exact time a credential was checked out, which user performed the checkout, which target system the credential was intended for, and whether the session was approved by a policy or an administrator. They also capture session timeouts, rotation events, and often include a reference to a recorded session replay, making them both the authorization and verification record for the 02:15 activity.

  • DHCP lease logs from the jump box subnet

    Why it's wrong here

    DHCP lease logs from the jump box subnet are irrelevant because they only document the network layer dynamic address assignment process, such as IP addresses handed out, MAC addresses, and lease durations. They neither show a user identity, nor an authentication event, nor an approval workflow, so they cannot verify whether the privileged access at 02:15 was authorized. Furthermore, jump boxes are often assigned static IP addresses, which would make DHCP logs even less useful as they might not contain any entry for that host.

  • Printer server logs for the operations department

    Why it's wrong here

    Printer server logs for the operations department are entirely unrelated to privileged authentication or session authorization. These logs track print queue events, toner levels, paper jams, and at most the username of a person who submitted a print job, but they do not capture interactive logon sessions, credential checkout requests, or administrative approval workflows. There is no technical mechanism by which a printer server would record or validate a PAM session on a jump box, so this log source provides no evidentiary value for this investigation.

  • Web proxy logs for outbound browsing activity

    Why it's wrong here

    Web proxy logs for outbound browsing activity are not designed to capture local authentication or credential management events. While a proxy logs URLs, source IPs, and timestamps for HTTP/HTTPS traffic, it does not log a user's interactive login to a jump box, nor does it record whether a privileged credential was checked out from a vault or approved by an administrator. Even if the jump box agent made an outbound request at 02:15, the proxy log would only show the destination and not the privileged access authorization context, making it insufficient to answer the question of whether the access was legitimate.

About these practice questions

One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.