StudyToCert

All certifications / Security+ / Lessons

CompTIA Security+ SY0-701 · Domain 4: Security operations

Logs, SIEM correlation, alerting, SCAP, NetFlow

▶ Watch the overview video

Last reviewed September 25, 2026 · Leer en español

Logs are the records systems keep of what happened: logins, file access, configuration changes, network connections, errors. They are the raw material for detecting attacks, investigating incidents and proving compliance. On their own, logs are scattered across hundreds of systems in different formats. Security operations centralizes and analyzes them, often in a security operations center (SOC) staffed around the clock, and Security+ expects you to know the tools and data sources involved: security information and event management (SIEM), correlation and alerting, the Security Content Automation Protocol (SCAP) and NetFlow.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study Security+ for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the Security+ study plan