Cisco CyberOps Associate (CBROPS) 200-201Security MonitoringEasy

A SIEM administrator is configuring a new data source for a critical web application. To ensure effective security monitoring, which of the following log types should be prioritized for ingestion to provide insights into user authentication, authorization, and potential web-based attacks?

  1. APrinter usage logs
  2. BWeb server access logs and application audit logs
  3. CNetwork device configuration backups
  4. DSystem uptime logs
Show answer & explanation

Correct answer: B. Web server access logs and application audit logs

For a web application, web server access logs provide details on HTTP requests, user agents, and status codes (useful for detecting web-based attacks), while application audit logs track user authentication, authorization, and specific application actions, directly addressing the requirements.

Why the other options are wrong

  • A. Printer usage logs are irrelevant to monitoring a web application for authentication, authorization, or web attacks.
  • C. Network device configuration backups are for disaster recovery and auditing network changes, not web application security monitoring.
  • D. System uptime logs are basic system health indicators, not directly relevant to web application security events.

Web Application Logs

Records generated by web servers and applications detailing HTTP requests, user activity, errors, and security-relevant events.

  • Includes web server access logs, error logs, and application-specific audit logs.
  • Crucial for detecting SQL injection, XSS, broken authentication, and other web attacks.
  • Provides context for user behavior and application performance.

Memory trick: For a SIEM to truly see, logs from key places it must be!

More Security Monitoring questions