nerdexam
Cisco

200-201 · Question #6

An offline audit log contains the source IP address of a session suspected to have exploited a vulnerability resulting in system compromise. Which kind of evidence is this IP address?

The correct answer is B. corroborative evidence. Corroborative evidence refers to supporting evidence that adds credibility or strengthens existing evidence or claims. In this scenario, the source IP address found in the offline audit log serves as supporting or corroborating evidence indicating the potential source or origin…

Submitted by carlos_mx· Mar 6, 2026Host-Based Analysis

Question

An offline audit log contains the source IP address of a session suspected to have exploited a vulnerability resulting in system compromise. Which kind of evidence is this IP address?

Options

  • Abest evidence
  • Bcorroborative evidence
  • Cindirect evidence
  • Dforensic evidence

How the community answered

(22 responses)
  • A
    5% (1)
  • B
    86% (19)
  • C
    9% (2)

Explanation

Corroborative evidence refers to supporting evidence that adds credibility or strengthens existing evidence or claims. In this scenario, the source IP address found in the offline audit log serves as supporting or corroborating evidence indicating the potential source or origin of the suspected compromise. While it contributes to the overall understanding of the incident, it might not be the sole definitive evidence but supports the investigation by providing additional context or clues about the incident.

Topics

#forensic evidence#audit logs#incident response

Community Discussion

No community discussion yet for this question.

Full 200-201 Practice