nerdexam
CompTIA

SY0-701 · Question #268

An analyst is reviewing an incident in which a user clicked on a link in a phishing email. Which of the following log sources would the analyst utilize to determine whether the connection was…

The correct answer is A. Network. To determine whether the connection was successful after a user clicked on a link in a phishing email, the most relevant log source to analyze would be the network logs. These logs would provide information on outbound and inbound traffic, allowing the analyst to see if the…

Submitted by valeria.br· Mar 6, 2026Security Operations

Question

An analyst is reviewing an incident in which a user clicked on a link in a phishing email. Which of the following log sources would the analyst utilize to determine whether the connection was successful?

Options

  • ANetwork
  • BSystem
  • CApplication
  • DAuthentication

How the community answered

(35 responses)
  • A
    71% (25)
  • B
    3% (1)
  • C
    9% (3)
  • D
    17% (6)

Explanation

To determine whether the connection was successful after a user clicked on a link in a phishing email, the most relevant log source to analyze would be the network logs. These logs would provide information on outbound and inbound traffic, allowing the analyst to see if the user's system connected to the remote server specified in the phishing link. Network logs can include details such as IP addresses, domains accessed, and the success or failure of connections, which are crucial for understanding the impact of the phishing attempt.

Community Discussion

No community discussion yet for this question.

Full SY0-701 Practice