CompTIA Tech+ (FC0-U71)SecurityHard
A security analyst is investigating a suspected data breach where sensitive customer information may have been exfiltrated from a company server. To determine if any data was indeed copied and sent out of the network, which of the following log types would be MOST critical to review?
- AAuthentication logs
- BOperating system logs
- CFirewall logs
- DApplication logs
Show answer & explanationAnswer & explanation
Correct answer: C. Firewall logs
Firewall logs record all inbound and outbound network traffic, including source/destination IP addresses, ports, protocols, and data transfer volumes. These logs are critical for detecting data exfiltration, as they would show unusual outbound connections or large data transfers from internal servers.
Why the other options are wrong
- A. Authentication logs track login attempts, which are important for initial access, but not directly for data exfiltration.
- B. Operating system logs detail system events and errors, but not necessarily network exfiltration.
- D. Application logs provide details about software operations but less about network data movement.
Firewall Logs
Records generated by a firewall that document all network traffic attempts (allowed or denied), including source/destination IP addresses, ports, protocols, and data sizes.
- Crucial for network security monitoring.
- Shows attempted and successful connections.
- Essential for detecting data exfiltration and unauthorized access.
Memory trick: Logs: F.O.A.A. - Firewall for traffic, OS for system, Auth for logins, App for software.