ISC2 CC Security Operations Practice Question
A security operations center wants to improve detection of malicious activity on endpoints. Which TWO data sources provide the most direct endpoint-level evidence for identifying suspicious process execution? (Choose two.)
⚠ Common exam trap
The trap here is treating network metadata as equivalent to host telemetry; only sources that record executions on the endpoint directly answer what process ran.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Endpoint detection and response (EDR) telemetry
Detecting suspicious process execution requires host-based visibility into what actually ran. EDR telemetry provides rich process-level detail including command lines and parent-child relationships, while OS process accounting or audit logs offer a lighter but still direct record of executions. Network-oriented sources such as NetFlow, firewall deny logs, and DHCP lease logs describe traffic or addressing, not the processes on the endpoint, so they serve as supporting context rather than primary execution evidence.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Endpoint detection and response (EDR) telemetry
Why this is correct
EDR collects process creation, command-line arguments, parent-child relationships, file and registry changes, and network connections from the endpoint. This telemetry directly shows what executed and how, making it the strongest source for spotting suspicious process behavior such as an office document spawning a scripting interpreter. It also supports historical hunting, so analysts can trace the full execution chain rather than only a single alert.
- ✗
Firewall deny logs
Why it's wrong here
Firewall deny logs show blocked connection attempts at the network perimeter or host firewall. They indicate what was prevented, not what executed on the endpoint. A blocked outbound connection does not reveal the responsible process or its command line. While useful for understanding attempted command-and-control traffic, deny logs alone cannot identify suspicious process execution and must be correlated with host telemetry.
- ✗
NetFlow records
Why it's wrong here
NetFlow captures metadata about network conversations, such as source and destination IP addresses, ports, and byte counts, but it does not record which process generated the traffic. It can reveal unusual connections but cannot show command lines or process ancestry. For identifying suspicious process execution specifically, NetFlow provides context about network effects rather than direct evidence of what ran on the host.
- ✗
DHCP lease logs
Why it's wrong here
DHCP lease logs map IP addresses to MAC addresses over time. They help identify which device held a given address, supporting attribution during investigations, but they contain no information about processes, commands, or user activity. They are useful for network mapping and correlating other logs, yet they do not provide evidence of suspicious process execution on an endpoint.
- ✓
Operating system process accounting or audit logs
Why this is correct
Process accounting and OS audit facilities record executions, including user, time, and often the command invoked. This provides direct endpoint-level evidence of what ran, which is exactly what the SOC needs to detect suspicious execution. While less rich than EDR, it remains a valid host-based source and is useful on systems where full EDR agents cannot be deployed, such as certain legacy or restricted platforms.
Visual reference
Go deeper
Related to this question
Learn chapter
Network Security Foundations
Key term
NetFlow
NetFlow is a network protocol developed by Cisco that collects and monitors IP traffic data to provide visibility into network usage, performance, and security.
Key term
Firewall
A firewall is a network security system that monitors and controls incoming and outgoing traffic based on predetermined security rules to protect trusted internal networks from untrusted external networks.
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.