mediumMultiple Choice
ISC2 CC Practice Question: Implementing a security information and event…
A company is implementing a security information and event management (SIEM) system. Which data source is most critical for detecting an ongoing brute-force attack?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Authentication logs.
Authentication logs record successful and failed login attempts, which are directly indicative of brute-force attacks. Other logs may provide supporting information but are not as directly tied to the attack.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DNS logs.
Why it's wrong here
DNS logs record name resolution queries, so repeated authentication attempts against a host appear only indirectly, if at all, and cannot reveal failed logon patterns. They are tempting because DNS tunnelling and beaconing detection genuinely relies on them, but authentication or Windows security event logs are the critical source for brute-force detection.
- ✓
Authentication logs.
Why this is correct
Authentication logs record repeated failed logon attempts against accounts, revealing the volume and source pattern characteristic of brute-force activity. This satisfies the stem's requirement for the most critical data source for detecting an ongoing brute-force attack.
- ✗
Firewall logs.
Why it's wrong here
Firewall logs record permitted and denied connections by IP and port, so repeated attempts appear as many separate accepted or dropped sessions rather than authentication failures against one account. They are tempting because they reveal network-level scanning and port sweeps, which is the right source when hunting reconnaissance or lateral movement.
- ✗
Application logs.
Why it's wrong here
Application logs capture business transactions and errors, not the repeated authentication failures against a single account that signal brute forcing. They are tempting because they expose user activity, making them the correct source when investigating logic abuse, data tampering or input-validation faults within the application itself.
Go deeper
Related to this question
Learn chapter
Authentication and Authorization Methods
Key term
Authentication
Authentication is the process of verifying that someone or something is who or what it claims to be before granting access to a system or resource.
Key term
Event
An event is any identifiable occurrence or action in a computer system, network, or application that can be logged, monitored, or analyzed for security or operational purposes.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.