I4 Module Test: Logs and Event Monitoring
Demonstrate your understanding of log evidence, timestamps, event context, authentication, system, application, network, web, pattern analysis, event timelines, and integrated defensive review.
Readiness Check
Module Test Readiness
0/5 ready
Assessment Instructions
Complete All 25 Questions Carefully
Questions
25
One best answer for each question.
Recommended Goal
80%+
Review missed concepts before moving forward.
Evidence Rule
Context
Choose the answer that best preserves evidence and avoids unsupported claims.
Assessment Coverage
Eight Areas Covered by the Module Test
Log Foundations
What logs are, why defenders use them, source limitations, evidence quality, and the difference between records and conclusions.
Time and Event Context
Original timestamps, normalized timestamps, time zones, clock drift, collection delay, event IDs, providers, severity, and confidence.
Authentication Logs
Sign-ins, failures, MFA, lockouts, password changes, sessions, service identities, source context, and expected versus review-required patterns.
System and Application Logs
Processes, services, updates, permissions, dependencies, crashes, resource conditions, recovery, and root-cause analysis.
Network and Web Logs
DNS, firewall, proxy, web server, network-flow, endpoint, application, source, destination, ports, methods, paths, responses, and request IDs.
Pattern Analysis
Baselines, normal, expected, unusual, suspicious, administrative, failed, evidence-incomplete, prioritization, and false positives.
Timeline Construction
Normalization, correlation, confirmed order, likely order, uncertain order, parallel activity, causation, corroboration, and evidence gaps.
Integrated Review
Scope, source inventory, evidence chains, findings, confidence, impact, ownership, safe recommendations, validation, and residual risk.
Check Your Understanding
Module I4 Test: Logs and Event Monitoring
Choose your answers first. Explanations appear only after submission.
1. What is the strongest definition of a log?
2. Why should defenders preserve original log values?
3. What does event time represent?
4. What does collection time represent?
5. A workstation clock is two minutes slow. What is the strongest handling method?
6. Why must an event ID be interpreted with its provider?
7. What does a high-severity event directly prove?
8. What does a successful sign-in directly prove?
9. What is a common expected cause of repeated sign-in failures after a password reset?
10. What does an account lockout directly prove?
11. Why should MFA events be reviewed with sign-in events?
12. What is the difference between a symptom and a root cause?
13. What does a service restart directly prove?
14. Why should application logs be correlated with system logs?
15. What does high CPU usage directly prove?
16. What does an allowed firewall event directly prove?
17. What does a DNS query directly prove?
18. What does a large network flow directly prove?
19. Why can one internal source address represent many users?
20. What is the best distinction between unusual and suspicious activity?
21. What should happen when important evidence is missing?
22. Which pattern deserves the highest review priority?
23. What does uncertain order mean in an event timeline?
24. Why can events close in time still be unrelated?
25. What is the best first step in an integrated multi-source log review?
Defender Habits
Post-Test Review Checklist
Key Takeaways
What You Should Remember
Module Completion
Module I4 Assessment Complete
Return to the module homepage and confirm that all eight lesson cards and the module test open correctly before committing the completed module.