High School IntermediateModule I425-Question Assessment

I4 Module Test: Logs and Event Monitoring

Demonstrate your understanding of log evidence, timestamps, event context, authentication, system, application, network, web, pattern analysis, event timelines, and integrated defensive review.

Readiness Check

Module Test Readiness

0/5 ready

Assessment Instructions

Complete All 25 Questions Carefully

Questions

25

One best answer for each question.

Recommended Goal

80%+

Review missed concepts before moving forward.

Evidence Rule

Context

Choose the answer that best preserves evidence and avoids unsupported claims.

Read every choice before revealing the answer. The strongest option will usually preserve original evidence, correlate multiple sources, state limitations, and recommend the narrowest authorized defensive action.

Assessment Coverage

Eight Areas Covered by the Module Test

1

Log Foundations

What logs are, why defenders use them, source limitations, evidence quality, and the difference between records and conclusions.

2

Time and Event Context

Original timestamps, normalized timestamps, time zones, clock drift, collection delay, event IDs, providers, severity, and confidence.

3

Authentication Logs

Sign-ins, failures, MFA, lockouts, password changes, sessions, service identities, source context, and expected versus review-required patterns.

4

System and Application Logs

Processes, services, updates, permissions, dependencies, crashes, resource conditions, recovery, and root-cause analysis.

5

Network and Web Logs

DNS, firewall, proxy, web server, network-flow, endpoint, application, source, destination, ports, methods, paths, responses, and request IDs.

6

Pattern Analysis

Baselines, normal, expected, unusual, suspicious, administrative, failed, evidence-incomplete, prioritization, and false positives.

7

Timeline Construction

Normalization, correlation, confirmed order, likely order, uncertain order, parallel activity, causation, corroboration, and evidence gaps.

8

Integrated Review

Scope, source inventory, evidence chains, findings, confidence, impact, ownership, safe recommendations, validation, and residual risk.

Check Your Understanding

Module I4 Test: Logs and Event Monitoring

Choose your answers first. Explanations appear only after submission.

1. What is the strongest definition of a log?

2. Why should defenders preserve original log values?

3. What does event time represent?

4. What does collection time represent?

5. A workstation clock is two minutes slow. What is the strongest handling method?

6. Why must an event ID be interpreted with its provider?

7. What does a high-severity event directly prove?

8. What does a successful sign-in directly prove?

9. What is a common expected cause of repeated sign-in failures after a password reset?

10. What does an account lockout directly prove?

11. Why should MFA events be reviewed with sign-in events?

12. What is the difference between a symptom and a root cause?

13. What does a service restart directly prove?

14. Why should application logs be correlated with system logs?

15. What does high CPU usage directly prove?

16. What does an allowed firewall event directly prove?

17. What does a DNS query directly prove?

18. What does a large network flow directly prove?

19. Why can one internal source address represent many users?

20. What is the best distinction between unusual and suspicious activity?

21. What should happen when important evidence is missing?

22. Which pattern deserves the highest review priority?

23. What does uncertain order mean in an event timeline?

24. Why can events close in time still be unrelated?

25. What is the best first step in an integrated multi-source log review?

Defender Habits

Post-Test Review Checklist

Key Takeaways

What You Should Remember

1.Logs are evidence records, not automatic conclusions.
2.Time normalization must preserve original values and document every transformation.
3.Authentication, system, application, network, web, and endpoint sources answer different questions.
4.Severity, rarity, failure, success, denial, and volume require context before classification.
5.Timelines must distinguish confirmed, likely, uncertain, parallel, and unsupported order.
6.Integrated reviews should preserve evidence, separate evidence chains, state confidence, and recommend narrow authorized actions.

Module Completion

Module I4 Assessment Complete

Return to the module homepage and confirm that all eight lesson cards and the module test open correctly before committing the completed module.