Exam objective
SY0-701 4.9: Investigation Data Sources
Investigation Data Sources for Security+
This Security+ topic covers choosing the data source that best supports an investigation based on the question being asked and the evidence needed; Log data sources: firewall logs, application logs, endpoint logs, OS-specific security logs, IPS/IDS logs, network logs, and metadata; Investigation-supporting data sources: vulnerability scans, automated reports, dashboards, and packet captures; Recognizing what each source can and cannot show at Security+ depth, including limitations such as missing context, summarized data, encrypted traffic, retention windows, and clock accuracy.
Start first lesson3 lessons in this topic
Common mistakes to avoid
Learners often choose firewall logs for every network-related investigation. Firewall logs show allowed or denied traffic at a control point. They do not necessarily show application actions, endpoint process behavior, or packet payload details.
Learners often treat vulnerability scans as proof of an attack. A vulnerability scan shows exposure or weakness. It does not prove that an attacker exploited the weakness unless correlated with other evidence.
Learners often choose packet captures for every investigation because they seem most detailed. Packet captures are powerful, but logs, dashboards, and reports may answer the question faster.