Courseiva
Security Operations →mediumMultiple Select

ISC2 CC Security Operations Practice Question

A security operations center wants to improve detection of malicious activity on endpoints. Which TWO data sources provide the most direct endpoint-level evidence for identifying suspicious process execution? (Choose two.)

⚠ Common exam trap

The trap here is treating network metadata as equivalent to host telemetry; only sources that record executions on the endpoint directly answer what process ran.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Endpoint detection and response (EDR) telemetry

Detecting suspicious process execution requires host-based visibility into what actually ran. EDR telemetry provides rich process-level detail including command lines and parent-child relationships, while OS process accounting or audit logs offer a lighter but still direct record of executions. Network-oriented sources such as NetFlow, firewall deny logs, and DHCP lease logs describe traffic or addressing, not the processes on the endpoint, so they serve as supporting context rather than primary execution evidence.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Endpoint detection and response (EDR) telemetry

    Why this is correct

    EDR collects process creation, command-line arguments, parent-child relationships, file and registry changes, and network connections from the endpoint. This telemetry directly shows what executed and how, making it the strongest source for spotting suspicious process behavior such as an office document spawning a scripting interpreter. It also supports historical hunting, so analysts can trace the full execution chain rather than only a single alert.

  • ✗

    Firewall deny logs

    Why it's wrong here

    Firewall deny logs show blocked connection attempts at the network perimeter or host firewall. They indicate what was prevented, not what executed on the endpoint. A blocked outbound connection does not reveal the responsible process or its command line. While useful for understanding attempted command-and-control traffic, deny logs alone cannot identify suspicious process execution and must be correlated with host telemetry.

  • ✗

    NetFlow records

    Why it's wrong here

    NetFlow captures metadata about network conversations, such as source and destination IP addresses, ports, and byte counts, but it does not record which process generated the traffic. It can reveal unusual connections but cannot show command lines or process ancestry. For identifying suspicious process execution specifically, NetFlow provides context about network effects rather than direct evidence of what ran on the host.

  • ✗

    DHCP lease logs

    Why it's wrong here

    DHCP lease logs map IP addresses to MAC addresses over time. They help identify which device held a given address, supporting attribution during investigations, but they contain no information about processes, commands, or user activity. They are useful for network mapping and correlating other logs, yet they do not provide evidence of suspicious process execution on an endpoint.

  • ✓

    Operating system process accounting or audit logs

    Why this is correct

    Process accounting and OS audit facilities record executions, including user, time, and often the command invoked. This provides direct endpoint-level evidence of what ran, which is exactly what the SOC needs to detect suspicious execution. While less rich than EDR, it remains a valid host-based source and is useful on systems where full EDR agents cannot be deployed, such as certain legacy or restricted platforms.

Visual reference

Client DHCP Server 1 Discover (broadcast) 2 Offer (IP: 192.168.1.10) 3 Request (I accept) 4 Acknowledge (lease confirmed) DORA — the four-step DHCP lease process

About these practice questions

This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.