Cisco CyberOps Associate (CBROPS) 200-201Security MonitoringEasy

A security analyst is reviewing a custom application's log files after a report of anomalous behavior. The logs show numerous entries similar to: 'User: admin, Action: login, Status: Failed, SourceIP: 192.168.1.100, Timestamp: 2023-10-27 14:35:01'. The analyst needs to quickly filter these logs to show only successful administrative actions. Which log analysis technique would be most efficient for this task?

  1. AKeyword search for 'Failed'
  2. BCounting total log entries
  3. CRegular expression matching for 'User: admin' and 'Status: Success'
  4. DSorting logs by 'SourceIP'
Show answer & explanation

Correct answer: C. Regular expression matching for 'User: admin' and 'Status: Success'

Regular expressions provide a powerful and flexible way to search for specific patterns within text. To find 'successful administrative actions', the analyst needs to match both 'User: admin' and 'Status: Success'. A regular expression can combine these criteria to efficiently filter the logs for the exact desired entries.

Why the other options are wrong

  • A. Keyword search for 'Failed' would show failed attempts, which is the opposite of what is requested ('successful administrative actions').
  • B. Counting total log entries would only give a number and not provide the specific log entries requested.
  • D. Sorting by 'SourceIP' would organize logs by IP address but would not filter for 'successful administrative actions'.

Regular Expressions (Regex) for Log Analysis

A sequence of characters that defines a search pattern, primarily for use in pattern matching with strings, or string searching and 'find and replace' operations. Essential for parsing and filtering unstructured log data.

  • Powerful for complex pattern matching in text.
  • Used to extract specific fields or identify particular event types.
  • Common in SIEMs, scripting, and command-line tools (e.g., grep).

Memory trick: To find the right needle in the haystack, you need a precise magnet.

More Security Monitoring questions