Security+ Lesson

Security Log Sources for Security+

Last updated: 6/10/2026

Short answer

Investigation starts with a question. The best data source depends on what the investigator needs to prove, scope, or understand. Firewall logs are strong when the question is whether traffic was allowed or blocked between networks, hosts, ports, or zones. They can show source IP, destination IP, port, protocol, action, rule, time, and sometimes bytes. A firewall log can support questions such as whether a blocked connection occurred or whether a server received traffic from a suspicious address. It usually cannot show what happened inside an encrypted application session or what a process did on the endpoint.

Why it appears on the exam

SY0-701 4.9: Match firewall, application, endpoint, OS security, intrusion prevention system (IPS)/intrusion detection system (IDS), network logs, and metadata to investigation needs.

Key concepts

Concept 1

Required terms

firewall logs: records of traffic permitted, denied, rejected, or otherwise handled by a firewall rule or policy. application logs: records generated by an application, such as errors, authentication attempts, transactions, application programming interface (API) calls, or business events. endpoint logs: records from a workstation, server, mobile device, or endpoint security tool about host activity. OS-specific security logs: operating system security audit records such as logons, privilege use, service changes, process events, or policy changes.

Example

An investigator needs to know whether an internal server accepted inbound traffic from a suspicious external IP on TCP 443. Firewall logs are the first source.

Concept 2

How Security Log Sources works

Investigation starts with a question. The best data source depends on what the investigator needs to prove, scope, or understand. Firewall logs are strong when the question is whether traffic was allowed or blocked between networks, hosts, ports, or zones. They can show source IP, destination IP, port, protocol, action, rule, time, and sometimes bytes. A firewall log can support questions such as whether a blocked connection occurred or whether a server received traffic from a suspicious address. It usually cannot show what happened inside an encrypted application session or what a process did on the endpoint.

Example

A customer record was changed in a web portal. Application logs are most likely to show the account, request, transaction, or error tied to that business action.

Concept 3

Common confusion

Learners often choose firewall logs for every network-related investigation. Firewall logs show allowed or denied traffic at a control point. They do not necessarily show application actions, endpoint process behavior, or packet payload details.

Example

A workstation may have run a malicious PowerShell command. Endpoint logs or OS-specific security logs are more useful than a dashboard summary.

Concept 4

What to recognize

Match each log source to what it can best show; Identify metadata needed to correlate events across sources; Recognize limitations of a source, such as encrypted content, missing application context, or lack of endpoint visibility; Choose OS-specific security logs for logon, privilege, service, or audit events.

Example

An IDS alert reports a known exploit signature. IPS/IDS logs can show the matched signature and traffic details, but endpoint or application logs are needed to confirm impact.

Sample questions

Select an answer to reveal the explanation. For tracked practice and weak-area review, use the Cultiv8 app.

Q1.On the exam, this detail appears: An investigator needs to know whether an internal server accepted inbound traffic from a suspicious external IP on TCP 443. Firewall logs are the first source. Which answer matches it?

Q2.Read this Security+ situation: A customer record was changed in a web portal. Application logs are most likely to show the account, request, transaction, or error tied to that business action. What is the best match?

Q3.A security team needs to decide what this situation represents: A workstation may have run a malicious PowerShell command. Endpoint logs or OS-specific security logs are more useful than a dashboard summary. Which option fits?

Practice this lesson in Cultiv8

The app adds tracked practice, targeted remediation, saved session history, and future readiness scoring.

Continue in Cultiv8