312-39 · Question #149
Jason, a SOC Analyst with Maximus Tech, was investigating Cisco ASA Firewall logs and came across the following log entry: May 06 2018 21:27:27 asa 1: %ASA -5 - 11008: User 'enable_15' executed the…
The correct answer is A. Warning condition message. In the context of Cisco ASA Firewall logs, messages are categorized into different severity levels ranging from 0 (emergencies) to 7 (debugging messages). The log entry mentioned specifies a severity level of 5, denoted by "-5-" in the log entry. According to Cisco's…
Question
Jason, a SOC Analyst with Maximus Tech, was investigating Cisco ASA Firewall logs and came across the following log entry:
May 06 2018 21:27:27 asa 1: %ASA -5 – 11008: User 'enable_15' executed the 'configure term' command What does the security level in the above log indicates?
Options
- AWarning condition message
- BCritical condition message
- CNormal but significant message
- DInformational message
How the community answered
(39 responses)- A82% (32)
- B10% (4)
- C3% (1)
- D5% (2)
Explanation
In the context of Cisco ASA Firewall logs, messages are categorized into different severity levels ranging from 0 (emergencies) to 7 (debugging messages). The log entry mentioned specifies a severity level of 5, denoted by "-5-" in the log entry. According to Cisco's documentation, a severity level of 5 corresponds to a "Notification" level, which indicates a warning condition message. These messages are significant and highlight conditions that could potentially lead to more severe problems if not addressed. The execution of the 'configure term' command by 'enable_15' user, as noted in the log, is an example of a notable event that warrants attention, hence categorized under this severity level. "Cisco ASA Series Syslog Messages", Cisco Systems, Inc. "Understanding Logging Levels in Cisco ASA Security Appliances", Cisco Community.
Topics
Community Discussion
No community discussion yet for this question.