Courseiva
Security Operations →mediumMultiple Choice

ISC2 CC Security Operations Practice Question

A security analyst notices repeated failed login attempts from an internal IP address to a domain controller, followed by a successful login. Which log type is most likely to provide detailed evidence of this activity?

⚠ Common exam trap

The trap is assuming firewall logs capture login activity because they show IP addresses and connection attempts — candidates must recognize that only authentication logs record the success/failure outcome of credential-based logon events.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Authentication logs

Authentication logs record login attempts, successes, failures, source IP addresses, timestamps, and account names, making them the definitive source for investigating repeated failed logins followed by a successful login. Domain controllers log authentication events (e.g., Windows Security Event ID 4625 for failed logon and 4624 for successful logon) that directly capture this pattern. This is the primary evidence source for credential-based attacks like brute force or password spraying.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Application logs

    Why it's wrong here

    Application logs record events generated by application code, such as errors and transactions, not Windows account authentication. They would be relevant for a failing line-of-business app, but logon attempts against a domain controller appear in security auditing, not application channels.

  • ✗

    Firewall logs

    Why it's wrong here

    Firewall logs record permitted or denied connections by IP, port and protocol, not authentication outcomes or account names. They would confirm the internal host reached the domain controller, but the failed-then-successful logon pattern is captured in authentication events, not network flow records.

  • ✗

    System logs

    Why it's wrong here

    System logs capture operating system events such as service starts, driver faults and reboots, not per-account authentication attempts. They might show the domain controller's health, but the repeated failed logons followed by success are recorded as security audit events, not system channel entries.

  • ✓

    Authentication logs

    Why this is correct

    Authentication logs capture the granular Kerberos and NTLM events on the domain controller, recording each failed attempt (Event ID 4625) and the subsequent successful logon (Event ID 4624) with source IP, account name and logon type. This directly satisfies the stem's requirement for detailed evidence of the brute-force pattern.

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.