Security+ Lesson

Monitored Computing Resources for Security+

Last updated: 6/10/2026

Short answer

Security monitoring works only if the right resources produce useful signals. Systems are common monitoring targets because user endpoints and servers are where logins, malware detections, process starts, file changes, privilege use, service failures, and configuration events occur. A compromised workstation, a server with repeated failed logins, or a virtual machine running unexpected processes may all generate system telemetry.

Why it appears on the exam

SY0-701 4.4: Identify systems, applications, and infrastructure as common monitoring targets.

Key concepts

Concept 1

Required terms

systems: endpoints, servers, virtual machines, operating systems, or other compute resources that can generate security-relevant events. applications: software and services that process users, transactions, sessions, inputs, errors, and business logic. infrastructure: network, cloud, identity, storage, and platform components that support systems and applications. endpoint telemetry: security-relevant data from user or server systems, such as process, login, malware, or configuration events.

Example

Repeated failed local administrator logins on a server are system monitoring events.

Concept 2

How Monitored Computing Resources works

Security monitoring works only if the right resources produce useful signals. Systems are common monitoring targets because user endpoints and servers are where logins, malware detections, process starts, file changes, privilege use, service failures, and configuration events occur. A compromised workstation, a server with repeated failed logins, or a virtual machine running unexpected processes may all generate system telemetry.

Example

A web application records a sudden spike in failed password resets and input validation errors. Those are application logs.

Concept 3

Common confusion

Learners often treat infrastructure as only network hardware. In monitoring, infrastructure can also include cloud platforms, identity services, storage services, and other shared components that systems and applications depend on.

Example

A router reports an interface state change, and flow data shows unusual outbound traffic. That is infrastructure telemetry.

Concept 4

What to recognize

Match a monitoring signal to systems, applications, or infrastructure; Explain why applications need their own logs instead of relying only on network or endpoint events; Identify infrastructure telemetry in network, cloud, identity, or storage scenarios; Distinguish monitored resource categories from monitoring activities and tools.

Example

A cloud platform records creation of a public storage bucket. That infrastructure event may need alerting and response.

Sample questions

Select an answer to reveal the explanation. For tracked practice and weak-area review, use the Cultiv8 app.

Q1.On the exam, this detail appears: Repeated failed local administrator logins on a server are system monitoring events. Which answer matches it?

Q2.A security question includes this clue: A web application records a sudden spike in failed password resets and input validation errors. Those are application logs. Which term is being tested?

Q3.A Security+ scenario describes this situation: A router reports an interface state change, and flow data shows unusual outbound traffic. That is infrastructure telemetry. Which answer fits best?

Practice this lesson in Cultiv8

The app adds tracked practice, targeted remediation, saved session history, and future readiness scoring.

Continue in Cultiv8