CompTIA SecurityX (CAS-005)Security OperationsEasy

A security analyst is investigating a suspected insider threat. They need to determine if a specific user account accessed sensitive files outside of business hours and copied them to a removable drive. Which of the following log sources would provide the most relevant forensic evidence for this investigation?

  1. AWeb server access logs
  2. BEndpoint audit logs
  3. CFirewall logs
  4. DDNS server logs
Show answer & explanation

Correct answer: B. Endpoint audit logs

Endpoint audit logs (e.g., Windows Event Logs, Linux auditd logs) directly record user actions on a local system, including file access, external device connections, and process execution, making them the most relevant source for tracking user activity on a workstation.

Why the other options are wrong

  • A. Web server access logs track HTTP/HTTPS requests to web servers and would not show local file access or removable drive usage.
  • C. Firewall logs record network connection attempts and traffic flows but do not typically provide details on local file system operations or removable media usage.
  • D. DNS server logs record DNS queries and responses, which are used for name resolution but do not track local file system access or removable drive events.

Endpoint Audit Logs

Records generated by an operating system or security agent on an endpoint (workstation, server) that detail user activities, system events, file access, and device connections.

  • Crucial for forensic investigations.
  • Logs user logins/logouts, process execution, file operations.
  • Includes removable media connections.
  • Examples: Windows Event Logs, Linux auditd.

Memory trick: To solve the mystery, gather clues from the most direct source.

More Security Operations questions