ISC2 Certified in Cybersecurity (CC)Security OperationsEasy
A security analyst is investigating a potential data breach. They need to determine who accessed a critical server, when they accessed it, and what actions they performed. The analyst realizes that detailed records of system events, user activities, and network connections are crucial for this investigation. Which security operations practice is essential for providing this information?
- ALog management
- BPenetration testing
- CSecurity awareness training
- DVulnerability scanning
Show answer & explanationAnswer & explanation
Correct answer: A. Log management
Log management involves the collection, storage, and analysis of logs from various systems, providing the detailed historical records necessary for forensic investigations and auditing user and system activities.
Why the other options are wrong
- B. Penetration testing exploits vulnerabilities, not collects activity logs.
- C. Security awareness training educates users, but doesn't provide technical logs for investigations.
- D. Vulnerability scanning identifies weaknesses, not historical activity records.
Log Management
The process of collecting, storing, analyzing, and securing log data generated by IT systems and applications.
- Critical for incident response and forensics.
- Provides an audit trail of activities.
- Helps identify security incidents and policy violations.
Memory trick: Logs tell the story of what happened.