Exam objective

SY0-701 4.9: Investigation Data Sources

Security+ Topic

Investigation Data Sources for Security+

This Security+ topic covers choosing the data source that best supports an investigation based on the question being asked and the evidence needed; Log data sources: firewall logs, application logs, endpoint logs, OS-specific security logs, IPS/IDS logs, network logs, and metadata; Investigation-supporting data sources: vulnerability scans, automated reports, dashboards, and packet captures; Recognizing what each source can and cannot show at Security+ depth, including limitations such as missing context, summarized data, encrypted traffic, retention windows, and clock accuracy.

Start first lesson

3 lessons in this topic

Common mistakes to avoid

1

Learners often choose firewall logs for every network-related investigation. Firewall logs show allowed or denied traffic at a control point. They do not necessarily show application actions, endpoint process behavior, or packet payload details.

2

Learners often treat vulnerability scans as proof of an attack. A vulnerability scan shows exposure or weakness. It does not prove that an attacker exploited the weakness unless correlated with other evidence.

3

Learners often choose packet captures for every investigation because they seem most detailed. Packet captures are powerful, but logs, dashboards, and reports may answer the question faster.