Courseiva
mediumMultiple Choice

ISC2 CC Practice Question: Implementing a security information and event…

A company is implementing a security information and event management (SIEM) system. Which data source is most critical for detecting an ongoing brute-force attack?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Authentication logs.

Authentication logs record successful and failed login attempts, which are directly indicative of brute-force attacks. Other logs may provide supporting information but are not as directly tied to the attack.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    DNS logs.

    Why it's wrong here

    DNS logs record name resolution queries, so repeated authentication attempts against a host appear only indirectly, if at all, and cannot reveal failed logon patterns. They are tempting because DNS tunnelling and beaconing detection genuinely relies on them, but authentication or Windows security event logs are the critical source for brute-force detection.

  • ✓

    Authentication logs.

    Why this is correct

    Authentication logs record repeated failed logon attempts against accounts, revealing the volume and source pattern characteristic of brute-force activity. This satisfies the stem's requirement for the most critical data source for detecting an ongoing brute-force attack.

  • ✗

    Firewall logs.

    Why it's wrong here

    Firewall logs record permitted and denied connections by IP and port, so repeated attempts appear as many separate accepted or dropped sessions rather than authentication failures against one account. They are tempting because they reveal network-level scanning and port sweeps, which is the right source when hunting reconnaissance or lateral movement.

  • ✗

    Application logs.

    Why it's wrong here

    Application logs capture business transactions and errors, not the repeated authentication failures against a single account that signal brute forcing. They are tempting because they expose user activity, making them the correct source when investigating logic abuse, data tampering or input-validation faults within the application itself.

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.