High School IntermediateModule I4 of 17Defensive Only

I4: Logs and Event Monitoring

Learn how defenders read authentication, system, application, network, web, and endpoint logs, connect related events, and explain evidence without jumping to conclusions.

Module Snapshot

Intermediate

Track

I4 of 17

Module

8

Lessons

25 questions

Module test

Evidence before conclusions

This module adds log sources, event fields, timestamp normalization, authentication review, pattern analysis, event correlation, and timeline documentation.

Main Question

How do defenders connect separate event records into an accurate and useful explanation?

Students will compare timestamps, users, devices, applications, services, addresses, actions, results, baselines, and approved changes before deciding what is confirmed, likely, uncertain, or unsupported.

Safety Boundary

Every log, event, account, address, domain, process, device, application, service, file, request, and organization in this module is fictional. Practice stays read-only, authorized, and limited to supplied training evidence.

Professional Workflow

Collect, Normalize, Contextualize, Correlate, and Document

1

Collect

Gather the fictional log sources, systems, users, time window, retention details, and review question.

2

Normalize

Align timestamps, time zones, device names, user identities, event fields, source labels, and formats.

3

Contextualize

Connect events with asset roles, user roles, expected schedules, applications, owners, and approved changes.

4

Correlate

Link related events using time, users, devices, processes, services, addresses, sessions, and request identifiers.

5

Document

Record confirmed facts, likely explanations, alternate explanations, evidence gaps, confidence, impact, and next action.

Learning Objectives

What Students Will Be Able to Do

Explain what logs are, why systems create them, and how defenders use them.

Interpret timestamps, event IDs, providers, users, devices, processes, actions, results, and severity labels.

Review fictional authentication, system, application, network, web, and endpoint logs.

Compare current activity with approved baselines and expected business context.

Build a simple multi-source event timeline while separating facts from conclusions and evidence gaps.

Document findings, confidence, limitations, ownership, escalation, and safe defensive next actions.

Module Path

Eight Intermediate Lessons

Each lesson includes professional hooks, fictional log evidence, safe defensive labs, scenario decisions, a scored quiz, a checklist, and a portfolio prompt.

I4.1

Lesson 1

What Logs Are and Why They Matter

Understand what logs record, why systems create them, and how defenders use logs for visibility, troubleshooting, monitoring, and response.

Defensive Lab

Classify fictional event records by source, purpose, useful fields, owner, and evidence limitation.

Open →

I4.2

Lesson 2

Timestamps, Event IDs, and Context

Read timestamps, event IDs, providers, severity labels, users, devices, actions, results, and correlation fields in context.

Defensive Lab

Normalize fictional records with different time zones, clock offsets, event formats, and collection delays.

Open →

I4.3

Lesson 3

Authentication Logs

Interpret fictional successful and failed sign-ins, lockouts, MFA activity, password resets, account changes, and session evidence.

Defensive Lab

Review an authentication sequence and distinguish expected password-reset activity from a pattern that needs escalation.

Open →

I4.4

Lesson 4

System and Application Logs

Connect operating-system, service, process, update, application, configuration, error, and recovery records.

Defensive Lab

Correlate a fictional application failure with service, permission, update, owner, and change evidence.

Open →

I4.5

Lesson 5

Network and Web Logs

Interpret firewall, DNS, proxy, web server, and connection records using source, destination, port, protocol, request, response, and ownership context.

Defensive Lab

Trace a fictional web request across DNS, firewall, proxy, and server logs without inspecting real traffic.

Open →

I4.6

Lesson 6

Normal vs Suspicious Patterns

Compare current activity with approved baselines and evaluate timing, frequency, source, destination, privilege, failure, and change context.

Defensive Lab

Classify fictional patterns as expected, unusual, suspicious, administrative, failed, or evidence-incomplete.

Open →

I4.7

Lesson 7

Building a Simple Event Timeline

Normalize and combine events from multiple sources into a clear chronological narrative with facts, conclusions, gaps, and confidence.

Defensive Lab

Build a twenty-event fictional timeline using authentication, system, application, network, endpoint, and change records.

Open →

I4.8

Lesson 8

Log Review Lab

Combine log sources, time normalization, event context, pattern analysis, correlation, and documentation into one defensive review.

Defensive Lab

Complete a multi-source fictional log review and create an evidence-based report with safe recommendations.

Open →

Fake Evidence Preview

How Intermediate Log Evidence Connects

10:02:14

Authentication

Two failed sign-ins from training-laptop-12

Shows unsuccessful attempts from an expected device but does not yet explain the cause.

10:02:18

Application

Mail client reports stored credential rejected

Adds application context suggesting an automatic retry with an old saved password.

10:03:07

Support

User confirms password was changed minutes earlier

Provides human and change context that may explain the failed attempts.

10:03:31

Authentication

Successful sign-in and approved MFA challenge

Shows the expected device completed the updated authentication sequence successfully.

A strong conclusion uses the records together: authentication results, application behavior, approved password change, device context, MFA, timestamps, and the absence of continued failures.

Portfolio Outcome

Multi-Source Log Review Report

Students will build a fictional report containing source inventory, normalized timestamps, event fields, authentication, system, application, network, and web evidence, a correlated timeline, pattern analysis, confidence, limitations, and safe defensive recommendations.

Module Assessment

25-Question I4 Module Test

The test will cover log vocabulary, timestamps, event IDs, context, authentication, system, application, network, web, patterns, timelines, evidence limitations, and safe suspicious activity analysis. Answers stay hidden until submission.

Open Module Test
← Intermediate TrackStart I4.1 →