← Back

19 Architecture & Log Sources Practice Questions & Answers

Every Architecture & Log Sources practice question from the CompTIA CySA+ Practice Test, with the correct answer and a short explanation.

Start practice test →
  1. 1. Flow records from a core router show 4.2 GB transferred from a file server to an external address over forty minutes on TCP 443. Management asks which employee account moved the data. What do the flow records establish, and which source answers the question?

    • A.Flow records retain the session payload for later reconstruction, so the DNS resolver log is needed only to attach a readable name to that external address.
    • B.Flow records fix the two hosts, the port and the byte volume, but carry no account identity; the endpoint agent's process and logon telemetry names the user.✓ Answer
    • C.Flow records carry the authenticated user name inside their application field, so the web proxy log is needed only to recover the exact URL path that was requested.
    • D.Flow records already attribute the session to a person through the source address, so the DHCP lease table by itself converts that address into a named employee.

    A flow record is a summary of a conversation: addresses, ports, protocol, byte and packet counts, and timing. It has no field for a user, so on a multi-user file server it cannot say who acted. Only a source that observes the operating system from inside — an endpoint agent correlating the process, its parent and the interactive or network logon session — binds the transfer to an account.

    Source: CompTIA CySA+ CS0-004 Objective 1.1 (logging and log ingestion; network architecture) with NIST SP 800-92 guidance that flow data records connection metadata, not user identityReport a problem with this question

  2. 2. An analyst correlates a firewall log, a web server log and a domain controller log for the same intrusion. NTP failed on the domain controller three weeks ago and its clock now runs seven minutes ahead of the other two sources. What should the analyst do about the timeline?

    • A.Order the events by the collector's ingestion timestamp, since arrival order at the SIEM reproduces the order in which the events actually happened on the hosts.
    • B.Discard the domain controller entries as unreliable and build the timeline from the firewall and web server logs alone, whose clocks still agree with each other.
    • C.Convert every timestamp into the analyst's own local time zone, which removes the discrepancy because all three sources then sit on one single common scale.
    • D.Treat the sequence as unproven until each source's offset is measured and applied, rebuild the timeline against one reference clock, and restore NTP on the domain controller.✓ Answer

    Correlation depends on a shared time base. A seven-minute offset can invert cause and effect, making a response look like it preceded the request that caused it. Ingest time is not event time because queuing and forwarding delays vary per source, and re-expressing the same skewed values in another time zone shifts all of them equally without removing the skew. The offset must be measured, applied as a correction, and the underlying synchronisation fixed.

    Source: CompTIA CySA+ CS0-004 Objective 1.1 (time synchronization); NIST SP 800-92 log management, which requires a synchronized time source before cross-source correlationReport a problem with this question

  3. 3. Two plants write their application logs in local wall-clock time with no offset recorded in the entry. One plant observes daylight saving time; the other does not. An analyst must order events from both plants across the night the clocks changed. What is the correct assessment?

    • A.Timestamps are unambiguous because each host's operating system holds its zone internally, so the analyst may simply read the entries in the order they were written.
    • B.Timestamps with no recorded offset are ambiguous, and one wall-clock hour repeats across the change; normalise each entry to UTC as it is ingested.✓ Answer
    • C.Timestamps must be left exactly as written, because rewriting a recorded field during ingestion would destroy the tamper-evidence of the original log entries.
    • D.Timestamps matter only inside a single source, so cross-plant ordering should instead come from the sequence numbers that the collector assigns on arrival.

    A bare local timestamp is not a point in time until the offset is known, and during a backward daylight-saving change the same local hour occurs twice, so two entries an hour apart can read identically. Normalising to UTC at ingestion while retaining the original string preserves both the evidential record and a single orderable scale; collector sequence numbers only record arrival order, which transport delay can reverse.

    Source: CompTIA CySA+ CS0-004 Objective 1.1 (logging, time synchronization); NIST SP 800-92 recommendation to normalize event time to a single reference such as UTCReport a problem with this question

  4. 4. A SIEM parser maps web server logs into a common schema and, in doing so, discards the client source port and the query string. An analyst must tie one recorded request back to a specific workstation sitting behind a NAT gateway shared by 200 hosts. What is the right step?

    • A.Rely on the NAT gateway's translation table by itself, because it maps every outside session back to exactly one inside host without any reference to port numbers.
    • B.Search the normalised events for the workstation's private address, because a correctly built SIEM schema preserves the original inside address through translation.
    • C.Retrieve the raw unmodified log next to the normalised event, because the source port is the field that separates sessions sharing one translated address.✓ Answer
    • D.Accept the gap as permanent, because a normalised schema replaces the original record by design and any field dropped during parsing cannot be recovered afterwards.

    Normalisation is lossy: whatever the parser does not map is absent from the searchable event even though the collector may still hold the raw line. Behind address translation many hosts share one public address, and the translated source port is the only key that distinguishes their concurrent sessions, so the raw record plus the gateway's translation entry for that port and time identifies the host.

    Source: CompTIA CySA+ CS0-004 Objective 1.1 (log ingestion and normalization); NIST SP 800-92 guidance on retaining original log data alongside normalized recordsReport a problem with this question

  5. 5. A database audit log records a DROP TABLE statement executed by app_svc, the single pooled account the web application uses for every connection. Thirty staff were signed in to that application at the time. What does the database log establish?

    • A.It proves the database administration team ran the statement, because only administrative accounts are ever granted permission to drop a table in production.
    • B.It names the person responsible, because a connection pool always writes the originating end-user name into the same audit field as the service account.
    • C.It establishes nothing whatever, because pooled connections make a database audit trail unusable as evidence and it should be excluded from the investigation.
    • D.It names the application identity that issued the statement but not the person behind it, so the application's own session log must map that action to an end user.✓ Answer

    This is the classic source that records the outcome but not the actor. The database sees only the identity that authenticated to it, and with a shared pooled account that identity is the application, so the log proves what was done and when but not by whom. Attribution requires the application tier's own session or transaction log, which holds the authenticated end-user identity for the request that triggered the statement.

    Source: CompTIA CySA+ CS0-004 Objective 1.1 (logging as evidence; identity and access management) — shared service accounts break attribution at the data tierReport a problem with this question

  6. 6. The security event log on a compromised workstation contains a log-cleared entry and nothing earlier. The environment forwards workstation events to a central collector every few minutes. What is the accurate assessment of the available evidence?

    • A.The collector's copy cannot be relied upon, because an event not read from the host that produced it carries no weight as a record of that host's own activity.
    • B.The entries are gone for good, because clearing a local event log also purges the matching records that had previously been forwarded to the central collector.
    • C.The copies already forwarded to the collector still exist, so entries written before the clearing can be examined even though the local copy on the host is gone.✓ Answer
    • D.The clearing event is now the only usable evidence, so the investigation has to continue from disk artefacts and from an interview with the workstation's user.

    Centralised aggregation exists precisely for this: once an event has been forwarded it is outside the reach of an attacker who only holds the endpoint, so clearing the local log destroys the host copy and leaves the collector's copy intact. The clearing entry is itself a useful indicator, but it does not limit the investigation to local artefacts while forwarded records survive.

    Source: CompTIA CySA+ CS0-004 Objective 1.1 (centralized log collection and log integrity); NIST SP 800-92 rationale for forwarding logs off the generating hostReport a problem with this question

  7. 7. A network sensor logs a TLS session from a workstation to a suspicious host: server name indication, certificate details, byte counts and duration, with no payload visible. The analyst must determine which executable on the workstation opened that connection. What is the best source?

    • A.Decrypt the stored capture using the certificate seen in the session, which exposes the client process name inside the application layer headers of the stream.
    • B.Examine the DNS resolver log for that same host name, which records the requesting process beside the query because name resolution happens per application.
    • C.Query the endpoint agent's process and connection telemetry, which binds each outbound socket to the process, its parent and the account that launched it.✓ Answer
    • D.Review the firewall's session table for the workstation, which lists the client application behind every permitted flow once inspection is enabled on the rule.

    A network view stops at the socket: it can identify the peers, the negotiated name and the volume, but nothing in the packets states which local program owns the connection, and a server certificate cannot decrypt a session negotiated with ephemeral key exchange. Endpoint telemetry observes the socket table from inside the operating system, which is what links the flow to a process, its parent and its user.

    Source: CompTIA CySA+ CS0-004 Objective 1.1 (operating system concepts; logging) — endpoint telemetry supplies process-to-connection attribution that network telemetry cannotReport a problem with this question

  8. 8. A building-management controller sits on a segmented operational technology network. Its vendor withdraws support if any software is installed on it, so no endpoint agent is possible. The analyst must establish whether the controller is contacting an external address. What fits the constraint?

    • A.Capture and examine the traffic crossing the segment boundary from a network sensor, which records the controller's sessions without touching the device itself.✓ Answer
    • B.Install the endpoint agent in monitoring-only mode for a week, since passive collection does not alter the controller's supported software configuration in any way.
    • C.Read the controller's own local event log through its management interface, which lists each outbound session it has opened with source and destination addresses.
    • D.Run a credentialed vulnerability scan against the controller, whose authenticated checks enumerate the host's active network connections as part of the profile.

    Where a host cannot be instrumented, the network view is the only view, and this is why passive monitoring is the standard approach on operational technology networks: a sensor fed from a boundary tap or mirror observes the device's sessions while adding nothing to it. Installing an agent still changes the software state, and a credentialed scan authenticates to the device, both of which the stated support condition forbids.

    Source: CompTIA CySA+ CS0-004 Objective 1.1 (operational technology constraints; network architecture and monitoring placement)Report a problem with this question

  9. 9. Two servers suspected of lateral SMB movement sit in the same VLAN on the same switch. The only network sensor is at the internet edge, and it shows no traffic between them. What is the correct reading of that silence?

    • A.The traffic between two hosts in one VLAN never reaches an edge sensor, so its silence proves nothing; visibility needs host telemetry or a sensor inside that segment.✓ Answer
    • B.The empty sensor record shows no lateral movement occurred, because any SMB session between two internal servers is routed through the organisation's edge device.
    • C.The edge sensor missed the sessions because SMB traffic is encrypted in transit, so enabling decryption on that sensor would surface the internal connections.
    • D.The sensor's record is incomplete because its rule set excludes private address ranges, so widening those rules will recover the earlier sessions retrospectively.

    Sensor placement decides what can be observed at all. Hosts in the same broadcast domain exchange frames through the switch without crossing any routed boundary, so a sensor at the edge never sees that conversation and its absence of records is not evidence of absence of activity. Observing east-west traffic requires endpoint telemetry or a sensor fed from inside the segment, such as a mirror of the relevant switch ports.

    Source: CompTIA CySA+ CS0-004 Objective 1.1 (network architecture; segmentation and monitoring placement) — segmentation limits lateral movement but does not itself observe itReport a problem with this question

  10. 10. Workstations are permitted to reach any external address directly on TCP 443 and there is no web proxy. A manager asks for the list of URLs one workstation visited last Tuesday. What is the accurate answer?

    • A.The available records hold only host names and addresses, so URL-level evidence would require egress through an inspecting proxy that logs requests.✓ Answer
    • B.The firewall's permit log already records the full request URL for each allowed session, so filtering that log by the workstation's address answers it directly.
    • C.The DNS resolver log reconstructs the visited URLs, because each resolved name is written once per page request together with the path that was requested.
    • D.The workstation's browser history is authoritative here, because a local browser store cannot be edited by its user and is retained for an unlimited period.

    Evidence exists only where an architecture creates a record. A firewall logs the five-tuple, not the request line, and a resolver log holds the queried name with no path, so with direct egress the most an analyst can reconstruct is which hosts were contacted. Forcing outbound web traffic through a proxy chokepoint is what produces URL-level evidence, and browser history is user-modifiable and locally bounded.

    Source: CompTIA CySA+ CS0-004 Objective 1.1 (network architecture; logging coverage) — egress control placement determines what request-level evidence existsReport a problem with this question

  11. 11. Objects in a cloud storage bucket were deleted over a weekend. Available sources include the guest logs of a virtual machine that mounted the bucket, virtual network flow logs, and the provider's audit trail. Which source names the identity that issued the delete calls?

    • A.The virtual network flow log, which records each API session to the storage endpoint together with the identity that was presented in the request headers.
    • B.The provider's control-plane audit trail, which records each management API call with its calling identity, source address and time of the request.✓ Answer
    • C.The guest operating system log of the virtual machine that mounted the bucket, which records the file deletions carried out against that mounted path.
    • D.The storage service's read-request log, which captures retrievals only and is therefore the service's definitive record of who removed those objects.

    In a cloud environment the authoritative record of who did what to a resource lives in the control plane, because the action is an authenticated management API call rather than an operating system event. Flow logs summarise connections and cannot see request identity inside a TLS session, a guest log only reflects what that one instance did through its own mount, and a read-only access log by definition does not record deletions.

    Source: CompTIA CySA+ CS0-004 Objective 1.1 (infrastructure and cloud architecture; logging) — control-plane audit logs are the record of management API activityReport a problem with this question

  12. 12. An alert names a suspicious file written inside a container. By the time the analyst looks, the orchestrator has already replaced that container with a fresh instance from the same image. What is the accurate position on the evidence?

    • A.Evidence survives only if it was shipped off the container while it ran, because replacing an instance discards its writable layer entirely.✓ Answer
    • B.The replaced container's writable layer is kept on the node by default, so the file can still be recovered from the node's local container storage directory.
    • C.The image held in the registry now contains the written file, because anything created at runtime is committed back into the image when a container exits.
    • D.The orchestrator's scheduling log holds the file's contents, because it captures an instance's complete state before terminating and replacing it.

    Containers are designed to be disposable, and an image is immutable, so runtime writes live in an ephemeral writable layer that is discarded with the instance. That is why container logging and file-integrity telemetry must be streamed to an external collector while the workload runs; once the orchestrator has replaced the instance, only what was already forwarded remains available.

    Source: CompTIA CySA+ CS0-004 Objective 1.1 (containerization and virtualization; log ingestion) — ephemeral workloads require off-host log shippingReport a problem with this question

  13. 13. A fraudulent transaction is traced to one invocation of a serverless function that ran for 900 milliseconds three days ago. There is no persistent host and no attached disk. How should the analyst proceed?

    • A.Work from the platform's invocation records and the function's own emitted telemetry, because the execution environment is gone and no persistent disk exists to acquire.✓ Answer
    • B.Request the underlying execution container from the provider under the support agreement, since environments are retained for a fixed window after each run.
    • C.Take a forensic image of the function's host instance from the provider portal, then hash it and examine the filesystem for artefacts left by the attacker.
    • D.Rebuild the environment from the deployment package and replay the request, treating the reconstructed instance as the primary evidence of what actually occurred.

    Serverless execution removes the artefact class that host forensics depends on: there is no instance to image and no disk to acquire, and the customer has no access to the provider's execution substrate. The durable record is what the platform and the function wrote while running — invocation identity, parameters, duration, outbound calls and application logs — which is why that telemetry must be configured in advance. A replayed instance is a reconstruction, not evidence of the original event.

    Source: CompTIA CySA+ CS0-004 Objective 1.1 (serverless and infrastructure concepts) — ephemeral compute shifts evidence from host artefacts to platform and application telemetryReport a problem with this question

  14. 14. A virtual machine is suspected of running a kernel-level rootkit, so its own event log and its endpoint agent output can no longer be trusted. What does the virtualisation layer add to the investigation?

    • A.Nothing independent at all, because a hypervisor records only resource scheduling and has no view of a guest's activity or of the traffic that guest sends.
    • B.A direct record of the guest's process creations, so hypervisor logs can stand in for the compromised agent's process telemetry on the affected machine.
    • C.An authoritative copy of the guest's own event log, because the hypervisor mirrors guest logging into its own store for every machine that it manages.
    • D.Evidence outside the guest's control: virtual switch traffic and management-plane actions on that machine, observed without relying on the guest.✓ Answer

    When code inside a guest may be lying, value comes from records produced beneath or beside it. The hypervisor and virtual networking layer see the machine's traffic and every administrative action taken on the virtual machine — power state, snapshot, reconfiguration, console access — and a rootkit inside the guest cannot edit those. What the hypervisor does not do is reproduce in-guest process detail, so it supplements rather than replaces endpoint telemetry.

    Source: CompTIA CySA+ CS0-004 Objective 1.1 (virtualization; log integrity) — records produced outside a suspect guest are not subject to that guest's tamperingReport a problem with this question

  15. 15. Staff reach a hosted expense application through the corporate identity provider using single sign-on. An analyst must establish both whether the second factor was satisfied at sign-in and which expense reports the account opened afterwards. Where does that evidence live?

    • A.Both facts sit in the identity provider's sign-in records, which log the authentication result and every later action taken by the user inside the application.
    • B.Both facts sit in the hosted application's audit log, because a federated service records the full authentication decision it received alongside in-application activity.
    • C.The authentication result and the second-factor outcome come from the identity provider; the in-application actions come from the service's own audit log.✓ Answer
    • D.Neither fact is available to the customer, because federation places both the sign-in record and the activity record under the hosting provider's sole control.

    Federation splits the evidence along the same line it splits the trust. The identity provider performs the authentication and therefore owns the record of the factors presented, the policy applied and the result, while the service provider only receives an assertion and records what the session then did inside the application. An investigation that touches both questions must collect from both sides.

    Source: CompTIA CySA+ CS0-004 Objective 1.1 (identity and access management: SSO and federation; logging) — the IdP owns authentication records, the SP owns activity recordsReport a problem with this question

  16. 16. An account was used at 02:00 to reach a federated cloud application, yet domain controller security logs for that hour contain no logon for the account. A junior analyst closes the alert as a false positive. How should this be judged?

    • A.The conclusion holds, because a federated application always validates the credential against the on-premises directory before granting any access.
    • B.The conclusion is wrong: authentication for a federated application happens at the identity provider, so its sign-in log holds the record.✓ Answer
    • C.The conclusion holds, because an account with no directory logon in that hour cannot have presented a credential anywhere in the environment.
    • D.The conclusion is unsafe only because the domain controller may have been offline, so confirming its uptime for that hour would settle it.

    Federation moves the authentication event to the identity provider, which issues an assertion the application trusts; in many designs no on-premises directory logon is generated at all. Searching the wrong system and treating an empty result as proof of nothing happening is a coverage error, not a finding. The analyst must query the identity provider's sign-in log for that account and hour before drawing any conclusion.

    Source: CompTIA CySA+ CS0-004 Objective 1.1 (SSO and federation; logging coverage) — absence of evidence in an out-of-path log is not evidence of absenceReport a problem with this question

  17. 17. An analyst must establish when a compromised account was added to a privileged group and from which workstation that account authenticated during the same period. Which single source best answers both questions?

    • A.The endpoint agent's process telemetry on the file server, which records each use of the privilege and the group change that had authorised it beforehand.
    • B.The directory service's security log, which records group membership changes and the authentication events that name the requesting workstation.✓ Answer
    • C.The network flow records for the domain controller, which show the account's authentication traffic and the group into which that change placed the account.
    • D.The privileged access vault's checkout history, which records each administrative session and the directory group granted at the moment of the checkout.

    Directory and identity infrastructure is the authoritative record of account state and of authentication, because it is the component that performs both operations. Its security log carries the membership change with the actor who made it and the ticket or logon events that identify the requesting workstation. Flow records hold no directory semantics, and a credential vault only covers sessions that went through the vault.

    Source: CompTIA CySA+ CS0-004 Objective 1.1 (identity and access management; logging) — the directory service records both account changes and authentication eventsReport a problem with this question

  18. 18. An investigation needs web proxy evidence from seven months ago. The proxy's stated retention is thirty days, and no archive of those records exists. What is the correct handling?

    • A.Report that no malicious browsing occurred in that period, since the proxy holds no record of a policy violation by the user concerned.
    • B.Ask the vendor to restore the expired entries, because an appliance keeps deleted log data recoverable for a year after expiry.
    • C.Raise the retention setting to twelve months and rerun the search, because the new value also applies to records already written.
    • D.State what the retained window can and cannot show, pursue sources that outlive the proxy, and record the missing months as a limitation.✓ Answer

    Retention bounds what a source can prove, and beyond that window the honest finding is that the source is silent, not that nothing happened. A retention change is prospective only, and expired entries are deleted rather than archived, so the analyst states the limitation explicitly and works from sources with longer lifetimes, then feeds the coverage gap back into logging requirements.

    Source: CompTIA CySA+ CS0-004 Objective 1.1 (logging: retention and coverage); NIST SP 800-92 guidance that retention policy determines available log evidenceReport a problem with this question

  19. 19. A firewall is configured to log denied connections only. A workstation is beaconing to an external command-and-control host over permitted TCP 443, and the firewall log contains no entries for that workstation. What is the correct reading?

    • A.The log is silent because encrypted sessions are exempt from firewall logging, so recording of this workstation resumes once decryption is enabled on the rule.
    • B.The workstation opened no outbound sessions in that period, because a permitted session would still have written an entry against the allow rule that carried it.
    • C.The log's silence reflects the logging configuration rather than the host's behaviour, so permitted traffic must be logged or observed from another source.✓ Answer
    • D.The log is silent because outbound sessions are only written when they close, so the missing entries will appear as soon as those long connections finally end.

    Logging level is part of coverage: a device that records only denials produces no record of the sessions that succeeded, which are exactly the ones that matter for command-and-control traffic riding an allowed rule. The absence of entries therefore says something about configuration, not about the host, and the fix is to log accepted sessions or to obtain the same visibility from flow records or endpoint telemetry.

    Source: CompTIA CySA+ CS0-004 Objective 1.1 (logging levels and log coverage) — deny-only logging creates a blind spot for successful connectionsReport a problem with this question

Practice questions based on the CompTIA CySA+ exam objectives. This site is not affiliated with or endorsed by CompTIA, and these are not real exam questions. CompTIA refreshes this exam periodically, runs two versions side by side during a transition, and sets the exam length, passing standard and eligibility terms — confirm the current objectives and the live exam code with CompTIA before you register. The real exam also includes performance-based items that a multiple-choice bank cannot reproduce, so pair this with hands-on practice. Official CySA+ exam objectives →