nerdexam
F5

401 · Question #25

Which data source is most valuable for detecting a security breach within an organization's network?

The correct answer is B. Application logs. Application logs are the most valuable source for detecting a security breach because they record system events, user activity, authentication attempts, file access, and network connections - giving security teams a detailed audit trail to identify anomalies like unauthorized…

Section 6: Threat Management and Incident Response

Question

Which data source is most valuable for detecting a security breach within an organization's network?

Options

  • ASocial media analytics
  • BApplication logs
  • CMarketing reports
  • DEmployee performance reviews

How the community answered

(58 responses)
  • A
    7% (4)
  • B
    74% (43)
  • C
    3% (2)
  • D
    16% (9)

Explanation

Application logs are the most valuable source for detecting a security breach because they record system events, user activity, authentication attempts, file access, and network connections - giving security teams a detailed audit trail to identify anomalies like unauthorized access, privilege escalation, or data exfiltration.

Social media analytics (A) tracks public online sentiment and brand mentions - useful for marketing, but provides no visibility into internal network activity. Marketing reports (C) summarize campaign performance and customer data, with no relevance to infrastructure security. Employee performance reviews (D) are HR documents that evaluate individual output and behavior over time, not real-time system events.

Memory tip: Think "logs = truth" - in security, logs are the ground truth of what happened on a system. If you need to know who did what and when inside a network, logs are always your first stop.

Topics

#application logs#breach detection#security monitoring#data sources

Community Discussion

No community discussion yet for this question.

Full 401 Practice