Cisco CyberOps Associate (CBROPS) 200-201Host-Based AnalysisHard
A security operations center (SOC) analyst is investigating a potential data exfiltration attempt from an internal server. The server's endpoint detection and response (EDR) agent has alerted on unusual outbound network connections from a non-standard process. To confirm if sensitive data has left the system, which specific host-based log file or event type on a Linux server would provide the most direct evidence of file access and transfer, specifically relating to the process's actions?
- AAudit logs (e.g., audit.log via auditd)
- BKernel logs (/var/log/kern.log)
- CApache access logs
- D/var/log/syslog
Show answer & explanationAnswer & explanation
Correct answer: A. Audit logs (e.g., audit.log via auditd)
Audit logs, specifically those generated by `auditd` on Linux, provide granular, configurable records of system calls, including file access, execution, and network connections by specific processes, making them ideal for tracking data access and potential exfiltration.
Why the other options are wrong
- B. Kernel logs record kernel-level events and errors, not detailed user-space process file access or network transfer data relevant to exfiltration.
- C. Apache access logs track web server requests, not general file access or outbound connections by arbitrary processes.
- D. Syslog contains general system messages but lacks the granular detail of file access by specific processes for forensic purposes.
Linux Audit Logs
System-level logs on Linux, typically managed by `auditd`, that record detailed information about system calls, file access, and process activity.
- Provides granular forensic data.
- Records user and process actions.
- Configurable to monitor specific events (e.g., file reads, writes, executions).
Memory trick: When a penguin's files go missing, check the 'audit' trail, not just the general 'sys' talk.