A security analyst is investigating a workstation that is suspected of outbound communication to a command-and-control server. During the investigation, the analyst discovered that logs on the endpoint were deleted. Which of the following logs would the analyst most likely look at next?
Choose an answer
Tap an option to check your answer.
Correct answer: Firewall.
Why this is the answer
The firewall logs are the most likely next place to look because they record network connection attempts, both inbound and outbound, even if endpoint logs were deleted. This makes them a crucial source for identifying suspicious outbound communication to a command-and-control server. IPS (Intrusion Prevention System) logs are valuable for detecting and blocking threats, but they might not capture all connection attempts, especially if the C2 traffic is obfuscated or uses non-standard ports. ACL (Access Control List) logs track access to specific resources but are less focused on general network connection attempts. Windows security logs would be ideal if available, but the question states they were deleted on the endpoint.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed