SSCP Systems Security Certified PractitionerSecurity Operations and AdministrationMedium

A security analyst is investigating a potential data exfiltration incident. During the investigation, the analyst discovers that a critical server's log files have been intentionally deleted, hindering the ability to trace the attacker's actions. Which of the following security controls would have been MOST effective in preventing this specific issue?

  1. ADeploying an advanced Endpoint Detection and Response (EDR) solution.
  2. BRegular security awareness training for all employees.
  3. CEnhancing network intrusion detection system (NIDS) capabilities.
  4. DImplementing a centralized, write-once, read-many (WORM) log management system.
Show answer & explanation

Correct answer: D. Implementing a centralized, write-once, read-many (WORM) log management system.

A centralized, write-once, read-many (WORM) log management system ensures that log files, once written, cannot be altered or deleted, thereby preserving critical forensic evidence even if an attacker gains control of a server.

Why the other options are wrong

  • A. An EDR solution can detect malicious activities but might not prevent the deletion of logs if the attacker has sufficient privileges and the logs are stored locally without WORM protection.
  • B. Security awareness training helps prevent initial compromises but does not directly protect log integrity once a system is compromised.
  • C. NIDS monitors network traffic for suspicious activity but does not protect the integrity of log files stored on an internal server.

WORM Log Management

Write-Once, Read-Many (WORM) log management systems ensure that log data, once recorded, cannot be altered or deleted, providing an immutable audit trail for security investigations.

  • Ensures log integrity and immutability.
  • Crucial for forensic investigations and compliance.
  • Prevents attackers from covering their tracks.
  • Often involves centralized storage.

Memory trick: Immutable logs are the bedrock of reliable investigations.

More Security Operations and Administration questions