CompTIA Security+ guideHigh-value skills
Security+ Log Analysis and Security Operations
Security Operations is 28% of SY0-701. These synthetic logs show how to decide what the lines support and what they do not.
Short answer
Security Operations is 28% of the SY0-701 blueprint, the largest domain weight, and it includes using logs and other data to support an investigation. Read a log for what changed: a new privilege, a denied path, or a process. Every log on this page is synthetic. A practice explanation is not a claim about a real incident, and it is not a recalled performance-based question.
Why this domain gets the time
CompTIA lists Security Operations at 28% of SY0-701. That is a blueprint weight, not a promise of 25 questions. Inside it, the objectives include monitoring, identity, firewall and detection tools, incident response, and data sources such as logs. The skill is not “I have seen a SIEM.” The skill is saying what a line supports. What to do after the line is confirmed is the incident response guide.
The lines below were written for this page. Addresses in 192.0.2.0/24 and 203.0.113.0/24 are documentation ranges. They are not a leaked item and not a real customer.
Failed logins, then a new administrator
| Time | Source | Event |
|---|---|---|
| 14:02 | 192.0.2.15 | Failed login, user sam |
| 14:02 | 192.0.2.15 | Failed login, user sam |
| 14:03 | 192.0.2.15 | Successful login, user sam |
| 14:04 | 192.0.2.15 | Created local administrator temp-admin |
The two failures are compatible with a mistyped password. They do not, by themselves, prove an attack. The successful login shows that sam’s account worked from that address. The following line changes the host: someone who just authenticated created another administrator. That is the line to investigate first. Resetting a screensaver, or closing the ticket because “the login eventually worked,” ignores the privilege change.
What you still do not know: whether sam was at the keyboard, whether the account is shared, or whether temp-admin was a legitimate break-glass step that someone forgot to record. The log supports the privilege change. It does not finish the incident.
A firewall deny that is doing its job
| Time | Action | Detail |
|---|---|---|
| 09:10 | Deny | 203.0.113.10 to 192.0.2.40, TCP 445 |
| 09:11 | Allow | 192.0.2.20 to 192.0.2.40, TCP 443 |
TCP 445 is commonly used for Windows file sharing. The deny says the firewall refused that attempt from a documentation address on the public side of this story. That is the control working, not proof that a file was stolen. The allow is a different service, from an internal address. Do not “fix” the deny by opening 445 to the outside because a user would find that more convenient. Ask whether 192.0.2.20 is supposed to reach the web service, and whether anyone is supposed to mount a file share from 203.0.113.10. Those are two questions.
A process, not just an address
An endpoint tool reports that a process named invoice-helper started under a user, then contacted 203.0.113.50, and the user’s documents began changing extensions. The firewall may later show the connection. The endpoint event explains the process. Endpoint detection is the tool that sees the process. A perimeter rule that only knows addresses does not. Contain the host before you spend the hour tuning the firewall sentence. The PBQ guide uses the same “name the failure first” order.
How to practice without a dump
Cover the right-hand column of a table like this and say what you would do next, in one sentence. If your sentence does not mention the newest privilege, the denied service, or the process, you are narrating the clock instead of the event.
Try a short Security+ log decision in multiple choice. The web set will not stream a SIEM. It will ask which event matters and why.
Trust the source
Official sources
Exam policies can change. Use these primary sources for the most current details.