Chapter 22
Data Sources for Supporting Investigations
This chapter covers the following official Security+ exam objective:
4.9 Given a scenario, use data sources to support an investigation.
Essential Terms and Components
Log data
Firewall logs
Application logs
Endpoint logs
OS-specific security logs
IPS/IDS logs
Network logs
Metadata ...
Get CompTIA Security+ SY0-701 Exam Cram, 7th Edition now with the O’Reilly learning platform.
O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.