QuestionQ64

Log Management

Bob is a SOC analyst at a multinational corporation that uses a centralized file-sharing system to store confidential project documents. One morning, he notices that a few critical financial records on the shared server seem to have been altered without authorization. Further analysis shows that the version history confirms unexpected changes outside business hours. He now needs to investigate by reviewing the logs. Which log should he check to identify who accessed the files and when the modifications took place?

  • A Authentication logs
  • B Firewall logs
  • C Security logs
  • D Network logs
Explanation

Security logs contain file-system object-access audit events when file auditing is enabled and the files have appropriate audit settings. These events can record the account, object, access type, and time associated with access or modification activity, enabling investigation of unauthorized file changes.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!