nerdexam
CompTIA

SY0-701 · Question #965

During the investigation of a webmail log-in using compromised credentials, a security analyst needs to review information about the source IP for the log-in. Which of the following logs should the an

The correct answer is B. Application. Application logs for the webmail service contain details about authentication events, including the source IP address used during the compromised log-in.

Submitted by ricky.ec· Mar 6, 2026Security Operations

Question

During the investigation of a webmail log-in using compromised credentials, a security analyst needs to review information about the source IP for the log-in. Which of the following logs should the analyst retrieve?

Options

  • ANetwork
  • BApplication
  • CSystem
  • DFirewall

How the community answered

(41 responses)
  • A
    5% (2)
  • B
    73% (30)
  • C
    7% (3)
  • D
    15% (6)

Explanation

Application logs for the webmail service contain details about authentication events, including the source IP address used during the compromised log-in.

Community Discussion

No community discussion yet for this question.

Full SY0-701 Practice