SY0-701 Security Operations Practice Question
A privileged account is used on a jump box at 02:15, and the SIEM shows multiple interactive logons from the same account to different servers within 10 minutes. The administrator says they used a password vault for the session. Which log source best confirms whether the access was authorized?
⚠ Common exam trap
Test-takers frequently assume DHCP logs or generic server logs can validate authentication authorization, when in fact only the PAM audit trail provides the cryptographic proof of vault-mediated access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Privileged access management or password vault audit logs
The privileged access management (PAM) or password vault audit logs are the definitive source because they record exactly when a password was checked out, which user performed the checkout, and the specific session ID or ticket associated with the jump box use. Since the administrator claims the password vault was used, these logs will show the checkout event at 02:15 and the subsequent interactive logons, confirming whether the vault authorized the session. No other log source can tie the authentication to the vault's approval process.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Privileged access management or password vault audit logs
Why this is correct
Privileged access management (PAM) or password vault audit logs are the definitive source for validating the legitimacy of a privileged session initiated from a jump box. These logs record the exact time a credential was checked out, which user performed the checkout, which target system the credential was intended for, and whether the session was approved by a policy or an administrator. They also capture session timeouts, rotation events, and often include a reference to a recorded session replay, making them both the authorization and verification record for the 02:15 activity.
- ✗
DHCP lease logs from the jump box subnet
Why it's wrong here
DHCP lease logs from the jump box subnet are irrelevant because they only document the network layer dynamic address assignment process, such as IP addresses handed out, MAC addresses, and lease durations. They neither show a user identity, nor an authentication event, nor an approval workflow, so they cannot verify whether the privileged access at 02:15 was authorized. Furthermore, jump boxes are often assigned static IP addresses, which would make DHCP logs even less useful as they might not contain any entry for that host.
- ✗
Printer server logs for the operations department
Why it's wrong here
Printer server logs for the operations department are entirely unrelated to privileged authentication or session authorization. These logs track print queue events, toner levels, paper jams, and at most the username of a person who submitted a print job, but they do not capture interactive logon sessions, credential checkout requests, or administrative approval workflows. There is no technical mechanism by which a printer server would record or validate a PAM session on a jump box, so this log source provides no evidentiary value for this investigation.
- ✗
Web proxy logs for outbound browsing activity
Why it's wrong here
Web proxy logs for outbound browsing activity are not designed to capture local authentication or credential management events. While a proxy logs URLs, source IPs, and timestamps for HTTP/HTTPS traffic, it does not log a user's interactive login to a jump box, nor does it record whether a privileged credential was checked out from a vault or approved by an administrator. Even if the jump box agent made an outbound request at 02:15, the proxy log would only show the destination and not the privileged access authorization context, making it insufficient to answer the question of whether the access was legitimate.
Go deeper
Related to this question
Learn chapter
Identity and Access Management
Key term
Privileged access
Privileged access is a special level of permission that allows a user or system to perform high-impact actions like installing software, changing system settings, or accessing sensitive data across an IT environment.
Key term
Audit
An audit is a systematic, independent review of IT systems, processes, and controls to verify compliance with policies, standards, and regulations.
About these practice questions
One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.