ISC2 Certified in Cybersecurity (CC)Security OperationsMedium
A security analyst is investigating a suspected insider threat. They need to review the activities of an employee who recently resigned under suspicious circumstances. The investigation requires looking at all network access attempts, file modifications, and email communications from the past six months. Which security operations concept would be MOST crucial for gathering this historical data?
- ASecurity Monitoring
- BLog Management
- CSecurity Assessments
- DAsset Management
Show answer & explanationAnswer & explanation
Correct answer: B. Log Management
To investigate historical activities like network access, file modifications, and email communications over a six-month period, robust log management practices are essential. Logs provide the detailed, timestamped records needed for forensic analysis and investigation.
Why the other options are wrong
- A. Security monitoring focuses on real-time alerting; while it uses logs, the comprehensive historical review falls under log management's scope.
- C. Security assessments evaluate security posture at a point in time, not historical user activities.
- D. Asset management tracks inventory but doesn't record user actions or communications.
Log Management
The systematic process of collecting, storing, processing, analyzing, and securing log data from various systems to provide an audit trail for security and operational purposes.
- Essential for incident response and forensic investigations.
- Supports compliance requirements by providing historical records.
- Aids in detecting anomalies and potential threats.
Memory trick: Logs are the digital footprints of every user, revealing their past journeys.