Cisco CyberOps Associate (CBROPS) 200-201Security MonitoringEasy
A security analyst is reviewing a custom application's log files after a report of anomalous behavior. The logs show numerous entries similar to: 'User: admin, Action: login, Status: Failed, SourceIP: 192.168.1.100, Timestamp: 2023-10-27 14:35:01'. The analyst needs to quickly filter these logs to show only successful administrative actions. Which log analysis technique would be most efficient for this task?
- AKeyword search for 'Failed'
- BCounting total log entries
- CRegular expression matching for 'User: admin' and 'Status: Success'
- DSorting logs by 'SourceIP'
Show answer & explanationAnswer & explanation
Correct answer: C. Regular expression matching for 'User: admin' and 'Status: Success'
Regular expressions provide a powerful and flexible way to search for specific patterns within text. To find 'successful administrative actions', the analyst needs to match both 'User: admin' and 'Status: Success'. A regular expression can combine these criteria to efficiently filter the logs for the exact desired entries.
Why the other options are wrong
- A. Keyword search for 'Failed' would show failed attempts, which is the opposite of what is requested ('successful administrative actions').
- B. Counting total log entries would only give a number and not provide the specific log entries requested.
- D. Sorting by 'SourceIP' would organize logs by IP address but would not filter for 'successful administrative actions'.
Regular Expressions (Regex) for Log Analysis
A sequence of characters that defines a search pattern, primarily for use in pattern matching with strings, or string searching and 'find and replace' operations. Essential for parsing and filtering unstructured log data.
- Powerful for complex pattern matching in text.
- Used to extract specific fields or identify particular event types.
- Common in SIEMs, scripting, and command-line tools (e.g., grep).
Memory trick: To find the right needle in the haystack, you need a precise magnet.