SSCP Risk Identification, Monitoring, and Analysis Practice Question
A security analyst reviews the health dashboard of the organization's Security Information and Event Management (SIEM) platform and notices that event ingestion from the primary domain controllers stopped at 02:00, while all other log sources continue to report normally. Which of the following should the analyst investigate FIRST to determine why domain controller logs are missing?
⚠ Common exam trap
The trap here is assuming that a monitoring gap means the SIEM platform itself is broken, when a single silent source usually indicates a source-side collection or forwarding failure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The Windows Event Forwarding subscription and the collector service status on the domain controllers
When one log source class stops feeding a SIEM while others continue, the fault lies in the collection pipeline unique to that source, not in shared infrastructure. Windows Event Forwarding subscriptions and the Windows Event Collector service are the exact mechanisms that transport domain controller events, so checking subscription health and collector service state isolates the failure quickly before broader troubleshooting.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The network firewall rules governing outbound syslog traffic from all monitored hosts
Why it's wrong here
Firewall rules are a shared transport path, so a blocking change would simultaneously affect many source types rather than only domain controllers. Because the remaining sources still deliver events, the transport layer is demonstrably working, making a general firewall rule review a low-value first step compared with the source-specific collection components.
- ✗
The SIEM correlation rules that map domain controller event IDs to alert severity levels
Why it's wrong here
Correlation rules determine which ingested events become alerts and at what severity; they do not control whether events arrive at the platform. If events stopped at 02:00, the data never reached the correlation engine, so tuning rule logic or severity mappings would not restore ingestion and would waste the analyst's time during triage.
- ✓
The Windows Event Forwarding subscription and the collector service status on the domain controllers
Why this is correct
Missing events from a single source class while all other sources report normally points to the collection path specific to those hosts. Windows Event Forwarding subscriptions, the Windows Event Collector service, and the source-side forwarding service are the components that deliver domain controller events to the SIEM, so verifying their status and subscription health is the correct first diagnostic step.
- ✗
The retention and rollover settings on the SIEM storage volumes
Why it's wrong here
Storage retention and index rollover affect how long already-collected data remains searchable, not whether new events are accepted. Since every other log source continues to report normally, the storage tier is clearly functioning and accepting writes, which makes retention configuration an implausible explanation for a single source going silent.
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.