QuestionQ64
Log ManagementBob is a SOC analyst at a multinational corporation that uses a centralized file-sharing system to store confidential project documents. One morning, he notices that a few critical financial records on the shared server seem to have been altered without authorization. Further analysis shows that the version history confirms unexpected changes outside business hours. He now needs to investigate by reviewing the logs. Which log should he check to identify who accessed the files and when the modifications took place?
- A Authentication logs
- B Firewall logs
- C Security logs
- D Network logs
Community Discussion