CompTIA Tech+ (FC0-U71)SecurityMedium
A security analyst is investigating a suspected data breach where sensitive customer information may have been compromised. The analyst needs to review records of who accessed the application, what actions they performed, and when those actions took place. Which security control would provide this crucial information?
- AEncryption keys
- BAccess logs
- CAntivirus scans
- DFirewall logs
Show answer & explanationAnswer & explanation
Correct answer: B. Access logs
Access logs specifically record user activity, including who accessed a system or application, what resources they accessed, and the timestamps of those actions. This information is critical for forensic analysis during a data breach investigation.
Why the other options are wrong
- A. Encryption keys are used to secure data, but they do not record who accessed or acted upon that data.
- C. Antivirus scans detect and remove malware, but do not record user access and actions within a web application.
- D. Firewall logs focus on network traffic allowed or denied at the perimeter, not specific user actions within an application.
Access Logs
Records of user activity, including logins, resource access, and actions performed within a system or application, along with timestamps.
- Crucial for auditing and forensic investigations.
- Help identify unauthorized access or actions.
- Part of an effective accountability framework.
Memory trick: Logs reveal who did what, when.