nerdexam
CompTIA

SY0-701 · Question #739

A security analyst notices an increase in port scans on the edge of the corporate network. Which of the following logs should the analyst check to obtain the attacker's source IP address?

The correct answer is B. Firewall. A firewall log records inbound and outbound network traffic, including source and destination IP addresses, port numbers, and connection attempts. Since port scans involve probing various ports on a network, the firewall logs will provide visibility into the attacker's source…

Submitted by manish99· Mar 6, 2026Security Operations

Question

A security analyst notices an increase in port scans on the edge of the corporate network. Which of the following logs should the analyst check to obtain the attacker’s source IP address?

Options

  • AOS security
  • BFirewall
  • CApplication
  • DEndpoint

How the community answered

(54 responses)
  • A
    2% (1)
  • B
    81% (44)
  • C
    6% (3)
  • D
    11% (6)

Explanation

A firewall log records inbound and outbound network traffic, including source and destination IP addresses, port numbers, and connection attempts. Since port scans involve probing various ports on a network, the firewall logs will provide visibility into the attacker's source IP address and help the analyst assess the nature of the scanning activity.

Community Discussion

No community discussion yet for this question.

Full SY0-701 Practice