312-50V10 · Question #281
A company has hired a security administrator to maintain and administer Linux and Windows- based systems. Written in the nightly report file is the following: - Firewall log files are at the expected
The correct answer is D. Log the event as suspicious activity, continue to investigate, and act according to the site's. Firewall log files that decrease in size are inherently suspicious because logs should only grow or be rotated, never shrink - this warrants logging, investigation, and adherence to the site incident response policy.
Question
A company has hired a security administrator to maintain and administer Linux and Windows- based systems. Written in the nightly report file is the following:
- Firewall log files are at the expected value of 4 MB.
- The current time is 12am. Exactly two hours later the size has
decreased considerably.
- Another hour goes by and the log files have shrunk in size again.
Which of the following actions should the security administrator take?
Options
- ALog the event as suspicious activity and report this behavior to the incident response team
- BLog the event as suspicious activity, call a manager, and report this as soon as possible.
- CRun an anti-virus scan because it is likely the system is infected by malware.
- DLog the event as suspicious activity, continue to investigate, and act according to the site's
How the community answered
(31 responses)- A19% (6)
- B3% (1)
- C6% (2)
- D71% (22)
Why each option
Firewall log files that decrease in size are inherently suspicious because logs should only grow or be rotated, never shrink - this warrants logging, investigation, and adherence to the site incident response policy.
Reporting immediately to the incident response team before completing any investigation may be premature and lacks the evidence needed for the team to act effectively.
Calling a manager before following the formal site incident response policy bypasses established procedures and may not be the appropriate escalation path.
Running an antivirus scan is too narrow a response and does not address the likely cause of deliberate log tampering, nor does it follow proper incident handling procedures.
Log files shrinking is a strong indicator of tampering or log clearing, which is a classic anti-forensics technique used by attackers to cover tracks. The correct response is to document the anomaly, continue gathering evidence to understand the scope, and then follow the organization's established incident response policy - this ensures legal and procedural integrity rather than escalating prematurely or taking unilateral action.
Concept tested: Incident response procedures and log integrity anomalies
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf
Topics
Community Discussion
No community discussion yet for this question.