A security analyst is reviewing alerts in the SIEM related to potential malicious network traffic coming from an employee’s corporate laptop. The security analyst has determined that additional data about the executable running on the machine is necessary to continue the investigation. Which of the following logs should the analyst use as a data source?
Choose an answer
Tap an option to check your answer.
Correct answer: Endpoint.
Why this is the answer
Endpoint logs provide detailed information about activities occurring directly on a device, such as an employee's laptop. These logs capture data about executable processes, file system changes, memory usage, and network connections originating from the endpoint itself. This is crucial for understanding what an executable is doing on the machine. Application logs focus on specific software behavior, not necessarily the underlying executable details. IPS/IDS logs detect and prevent network intrusions but don't provide granular endpoint process data. Network logs monitor traffic flow but lack the internal context of what's running on a specific device.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed