CompTIA
SY0-701 · Question #965
During the investigation of a webmail log-in using compromised credentials, a security analyst needs to review information about the source IP for the log-in. Which of the following logs should the an
The correct answer is B. Application. Application logs for the webmail service contain details about authentication events, including the source IP address used during the compromised log-in.
Submitted by ricky.ec· Mar 6, 2026Security Operations
Question
During the investigation of a webmail log-in using compromised credentials, a security analyst needs to review information about the source IP for the log-in. Which of the following logs should the analyst retrieve?
Options
- ANetwork
- BApplication
- CSystem
- DFirewall
How the community answered
(41 responses)- A5% (2)
- B73% (30)
- C7% (3)
- D15% (6)
Explanation
Application logs for the webmail service contain details about authentication events, including the source IP address used during the compromised log-in.
Community Discussion
No community discussion yet for this question.