An organization experiences a cybersecurity incident involving a command-and-control server. Which of the following logs should be analyzed to identify the impacted host? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: Network, Firewall.
Why this is the answer
Network logs provide crucial information about traffic flow, source and destination IP addresses, ports, and protocols, which can pinpoint the internal host communicating with the command-and-control server. Firewall logs record allowed and denied connections, including source and destination IPs and ports, making them essential for identifying unauthorized outbound connections to a malicious server and the internal host initiating them. Application logs track activity within specific applications, not necessarily network connections. Authentication logs focus on user login attempts. DHCP logs assign IP addresses but don't detail ongoing network communications. Database logs track database queries and access, not network-level communication with external servers.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed