Certified Cloud Security Professional (CCSP)Cloud Security OperationsMedium
During a cloud incident response, the team determines that a critical database containing sensitive customer data has been exfiltrated. The next immediate step, after containing the breach, is to determine what specific data was accessed and by whom, to assess the impact and fulfill notification requirements. Which type of log data is most crucial for this specific activity?
- ACloud provider infrastructure logs
- BOperating system logs
- CNetwork flow logs
- DDatabase transaction logs
Show answer & explanationAnswer & explanation
Correct answer: D. Database transaction logs
Database transaction logs provide detailed records of specific queries, data accessed, and user activities within the database, which is critical for understanding what data was exfiltrated and by whom.
Why the other options are wrong
- A. Cloud provider infrastructure logs (e.g., API calls) might show access to the database *service* but not granular access *within* the database itself.
- B. Operating system logs provide system-level events but often lack the granularity of database-specific access details.
- C. Network flow logs show traffic volume and endpoints but not the specific data content or database queries.
Database Transaction Logs
Records of all changes and operations performed on a database, including data modifications, queries, user sessions, and timestamps, used for auditing, recovery, and forensic analysis.
- Essential for understanding 'what data' was accessed and 'by whom'.
- Provides granular detail on database activity.
- Crucial for data breach impact assessment.
Memory trick: Database logs tell the story of every data touch.