Continue your lesson
Connect each term to the asset, threat, control, and evidence it affects.
Block 1 of 1Compare Firewall log · Packet capture · Endpoint log · Vulnerability scan
Current · 15 min
Compare Firewall log · Packet capture · Endpoint log · Vulnerability scan
Optional concept notes
Firewall log
Shows allowed or denied network connections matched by rules.
Packet capture
Preserves packet headers and payloads for detailed traffic analysis.
Cross-certificationNet+ ↔ Sec+
Packet capture
The core idea stays the same. The surrounding objective changes the evidence, decision, or task the exam asks for.
Endpoint log
Records host processes authentication activity and local security events.
Vulnerability scan
Reports detected weaknesses and affected assets at a point in time.
Complete one provider lesson, then answer four related questions. That is enough for today; more practice is optional.
Your lesson stays open here while the provider opens in another tab. Choose one source; the notes above are optional.
Practice the reasoning here
Use a fictional organization. Name the risk, choose the narrowest useful control, and state what evidence would prove the control worked.
- State the expected result before changing or testing anything.
- Name the observation, command, log, or report that would confirm it.
- Explain why the closest alternative does not fit the same requirement.
Check the whole objective
This unlocks objective 4.9 for recall. The latest checkpoint needs 70% or higher; a lower result puts the lesson back near the front of your timeline.