CompTIA SecurityX (CAS-005)Security OperationsMedium

An incident response team is investigating a potential insider threat. They need to analyze user activity on a critical file share to determine if any unauthorized access or data exfiltration occurred. Specifically, they want to see which users accessed which files, when, and what actions (read, write, delete) were performed. Which type of log would provide the most granular and relevant information for this investigation?

  1. AAntivirus logs
  2. BOperating System (OS) audit logs
  3. CFirewall logs
  4. DDNS logs
Show answer & explanation

Correct answer: B. Operating System (OS) audit logs

Operating System (OS) audit logs (e.g., Windows Security logs, Linux auditd logs) are designed to record detailed user actions on files, including who accessed what, when, and the specific operation performed (read, write, delete). This level of granularity is crucial for insider threat investigations on file shares.

Why the other options are wrong

  • A. Antivirus logs focus on malware detection and quarantine, not general user file access.
  • C. Firewall logs track network connections, not specific file access by users on a share.
  • D. DNS logs record domain name resolutions, irrelevant to file share access details.

OS Audit Logs

System-level logs generated by an operating system that record security-relevant events, such as user logins, file access attempts, privilege escalation, and process execution. They are critical for forensic analysis and compliance.

  • Records user actions on files and resources.
  • Includes timestamps, user IDs, and action types.
  • Essential for insider threat and forensic investigations.

Memory trick: For File Forensics, OS Audit Logs are the Gold Standard.

More Security Operations questions