4.9 Given a scenario, use data sources to support an investigation
Domain 4: Security Operations
This scenario-based objective tests whether you can pick the right data source to answer an investigative question. Group the sources in your head: log data includes firewall, application, endpoint, OS-specific security logs, IPS/IDS, network, and metadata; broader sources include vulnerability scan results, automated reports, dashboards, and packet captures. Questions typically describe what an analyst needs to prove — who authenticated, what connection was blocked, what a payload contained — and ask where to look. Firewall logs show allowed and denied connections but not payload; packet captures show payload but only if capture was already running; endpoint logs reveal process activity; authentication events live in OS security logs. Metadata from email headers, files, and mobile devices frequently answers timeline and attribution questions. Candidates stumble by defaulting to packet capture for everything or forgetting that dashboards summarize rather than provide forensic detail. Practice matching evidence needs to source capabilities, and remember that correlating multiple sources through a SIEM is often the strongest answer when a single log cannot tell the whole story.
What you must know
- firewall and IPS logs
- endpoint and OS logs
- packet captures
- metadata analysis
- vulnerability scan output
- dashboards vs raw logs
common pitfall · Candidates reach for packet captures as a universal answer, forgetting captures only exist if recording was already in place and that logs or metadata often answer the question faster.
Is objective 4.9 your weak spot?
The free readiness check finds your weakest objectives in 15 adaptive questions — then full access drills them until the gauge clears the cut line.
Check my readiness — free