ISC2 Certified in Cybersecurity (CC)Security PrinciplesMedium
A security analyst is reviewing logs and discovers that a user account, 'jsmith', attempted to log in to a critical server outside of business hours from an unknown IP address multiple times, failing each time. The system recorded all these attempts, including the timestamp, source IP, and username. Which security principle is primarily being supported by the system's ability to record these actions for later review?
- AAvailability
- BAuthentication
- CAccounting
- DAuthorization
Show answer & explanationAnswer & explanation
Correct answer: C. Accounting
Accounting (also known as auditing) involves tracking and logging user activities and system events. The system's ability to record login attempts, timestamps, and source IPs directly supports the accounting principle, enabling later review and accountability.
Why the other options are wrong
- A. Availability ensures systems are operational, which is not directly related to logging user actions.
- B. Authentication verifies the identity of a user, which is attempted here but not the focus of the logging itself.
- D. Authorization determines what an authenticated user can do, not the logging of their actions.
Accounting (Security)
The process of tracking user activities, system events, and resource consumption for auditing, billing, and accountability purposes.
- Often referred to as auditing.
- Records who did what, when, and from where.
- Crucial for forensics, compliance, and identifying malicious activity.
Memory trick: Authenticate who you are, Authorize what you can do, Account for what you did.