When an alert fires or an incident is suspected, analysts need evidence to understand what happened. Different data sources reveal different parts of the story, and knowing which source answers which question is a core skill for both the exam and real work. Security+ lists log data (firewall, application, endpoint, OS security, IPS/IDS, network, metadata) and other data sources such as vulnerability scans, automated reports, dashboards and packet captures. Good investigations combine several sources to build a reliable timeline. The time to think about data sources is before an incident: if a log is not collected, or is kept for only seven days, it will not be there when you need it three weeks later.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.