StudyToCert

All certifications / Security+ / Lessons

CompTIA Security+ SY0-701 · Domain 4: Security operations

Investigation data sources

▶ Watch the overview video

Last reviewed September 25, 2026 · Leer en español

When an alert fires or an incident is suspected, analysts need evidence to understand what happened. Different data sources reveal different parts of the story, and knowing which source answers which question is a core skill for both the exam and real work. Security+ lists log data (firewall, application, endpoint, OS security, IPS/IDS, network, metadata) and other data sources such as vulnerability scans, automated reports, dashboards and packet captures. Good investigations combine several sources to build a reliable timeline. The time to think about data sources is before an incident: if a log is not collected, or is kept for only seven days, it will not be there when you need it three weeks later.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study Security+ for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the Security+ study plan