nerdexam
CompTIA

SY0-701 · Question #194

An organization experiences a cybersecurity incident involving a command-and-control server. Which of the following logs should be analyzed to identify the impacted host? (Choose two.)

The correct answer is D. Network E. Firewall. Network logs (Option D): These logs can help identify network connections to the command-and- control server and provide information about source IP addresses (the impacted host) and destination IP addresses (the command-and-control server). Firewall logs (Option E): Firewall…

Submitted by daniela_cl· Mar 6, 2026Security Operations

Question

An organization experiences a cybersecurity incident involving a command-and-control server. Which of the following logs should be analyzed to identify the impacted host? (Choose two.)

Options

  • AApplication
  • BAuthentication
  • CDHCP
  • DNetwork
  • EFirewall
  • FDatabase

How the community answered

(15 responses)
  • A
    27% (4)
  • B
    7% (1)
  • C
    7% (1)
  • D
    47% (7)
  • F
    13% (2)

Explanation

Network logs (Option D): These logs can help identify network connections to the command-and- control server and provide information about source IP addresses (the impacted host) and destination IP addresses (the command-and-control server). Firewall logs (Option E): Firewall logs also track network traffic and can provide valuable information about source and destination IP addresses, helping identify the impacted host and its communication with the command-and-control server.

Community Discussion

No community discussion yet for this question.

Full SY0-701 Practice