CompTIA CySA+ (CS0-003)Incident Response and ManagementEasy
A security analyst is investigating a suspected phishing attempt. A user reported an email with a suspicious link, which was clicked. The analyst needs to determine if any malicious files were downloaded or executed on the user's workstation. Which of the following log types would provide the MOST direct evidence of such activity?
- AFirewall logs
- BMail server logs
- CEndpoint Detection and Response (EDR) logs
- DDNS server logs
Show answer & explanationAnswer & explanation
Correct answer: C. Endpoint Detection and Response (EDR) logs
EDR logs provide detailed visibility into endpoint activities, including process execution, file system changes, and network connections originating from the endpoint, making them ideal for detecting downloaded or executed malicious files.
Why the other options are wrong
- A. Firewall logs primarily show network traffic allowed or denied at the perimeter, not internal endpoint activity.
- B. Mail server logs track email delivery and content but do not show post-delivery actions on the recipient's machine.
- D. DNS logs show name resolution requests but not file downloads or program execution on the host.
EDR Logs
Endpoint Detection and Response (EDR) logs record activities on an endpoint, such as process execution, file system changes, and network connections, to detect and investigate security incidents.
- Provide deep visibility into endpoint behavior.
- Crucial for detecting post-exploitation activities.
- Collects data like process creation, file hashes, and network flows.
Memory trick: EDR sees all the endpoint's secrets.