SSCP Systems Security Certified PractitionerRisk Identification, Monitoring, and AnalysisMedium
A large enterprise is implementing a new security information and event management (SIEM) system. During the initial configuration, the security team is deciding which logs to prioritize for ingestion and analysis. They aim to focus on events that provide the clearest indicators of potential compromise or malicious activity. Which of the following log sources typically provides the richest data for identifying security incidents?
- APrinter usage logs
- BApplication logs (e.g., web server access, database queries)
- CPhysical access control logs
- DHVAC system logs
Show answer & explanationAnswer & explanation
Correct answer: B. Application logs (e.g., web server access, database queries)
Application logs, such as web server access logs and database query logs, contain detailed information about user interactions, data access, and application-specific errors or anomalies. This level of detail is crucial for detecting various types of attacks, from SQL injection to unauthorized data access, making them extremely valuable for security incident identification.
Why the other options are wrong
- A. Printer logs are less directly useful for detecting cyberattacks, primarily showing document printing.
- C. Physical access logs are important for physical security but less directly for cyber security incidents unless integrated for insider threat analysis.
- D. HVAC logs are related to environmental controls and have minimal relevance to cyber security incident detection.
Log Source Prioritization
The process of determining which security-relevant log data to collect and analyze first, based on its value for detecting threats.
- Focus on logs that show user activity, system changes, and network connections.
- High-value logs include operating system, application, network device, and security device logs.
- Aims to maximize detection capabilities with finite resources.
Memory trick: System, Network, Application: the core three for security logs.