200-201 · Question #186
Refer to the exhibit. An analyst received this alert from the Cisco ASA device, and numerous activity logs were produced. How should this type of evidence be categorized?
The correct answer is D. best. Alerts and activity logs directly from a Cisco ASA device are considered best evidence, as they are primary, original records generated by a security appliance.
Question
Refer to the exhibit. An analyst received this alert from the Cisco ASA device, and numerous activity logs were produced. How should this type of evidence be categorized?
Options
- Aindirect
- Bcircumstantial
- Ccorroborative
- Dbest
How the community answered
(37 responses)- A3% (1)
- C3% (1)
- D95% (35)
Why each option
Alerts and activity logs directly from a Cisco ASA device are considered best evidence, as they are primary, original records generated by a security appliance.
Indirect evidence requires inferences to connect it to a fact, whereas ASA logs are direct recordings of events.
Circumstantial evidence suggests a fact indirectly, unlike ASA logs which are direct records of security events.
Corroborative evidence supports or confirms other evidence, but ASA logs can stand as primary evidence on their own.
Best evidence refers to primary or original evidence, which has the highest probative value. Logs and alerts directly generated by a security device like a Cisco ASA are direct records of events and thus qualify as best evidence in incident response and forensics.
Concept tested: Types of digital evidence (Best Evidence)
Topics
Community Discussion
No community discussion yet for this question.