nerdexam
EC-Council

312-50V10 · Question #281

A company has hired a security administrator to maintain and administer Linux and Windows- based systems. Written in the nightly report file is the following: - Firewall log files are at the expected

The correct answer is D. Log the event as suspicious activity, continue to investigate, and act according to the site's. Firewall log files that decrease in size are inherently suspicious because logs should only grow or be rotated, never shrink - this warrants logging, investigation, and adherence to the site incident response policy.

Information Security and Ethical Hacking Fundamentals

Question

A company has hired a security administrator to maintain and administer Linux and Windows- based systems. Written in the nightly report file is the following:

  • Firewall log files are at the expected value of 4 MB.
  • The current time is 12am. Exactly two hours later the size has

decreased considerably.

  • Another hour goes by and the log files have shrunk in size again.

Which of the following actions should the security administrator take?

Options

  • ALog the event as suspicious activity and report this behavior to the incident response team
  • BLog the event as suspicious activity, call a manager, and report this as soon as possible.
  • CRun an anti-virus scan because it is likely the system is infected by malware.
  • DLog the event as suspicious activity, continue to investigate, and act according to the site's

How the community answered

(31 responses)
  • A
    19% (6)
  • B
    3% (1)
  • C
    6% (2)
  • D
    71% (22)

Why each option

Firewall log files that decrease in size are inherently suspicious because logs should only grow or be rotated, never shrink - this warrants logging, investigation, and adherence to the site incident response policy.

ALog the event as suspicious activity and report this behavior to the incident response team

Reporting immediately to the incident response team before completing any investigation may be premature and lacks the evidence needed for the team to act effectively.

BLog the event as suspicious activity, call a manager, and report this as soon as possible.

Calling a manager before following the formal site incident response policy bypasses established procedures and may not be the appropriate escalation path.

CRun an anti-virus scan because it is likely the system is infected by malware.

Running an antivirus scan is too narrow a response and does not address the likely cause of deliberate log tampering, nor does it follow proper incident handling procedures.

DLog the event as suspicious activity, continue to investigate, and act according to the site'sCorrect

Log files shrinking is a strong indicator of tampering or log clearing, which is a classic anti-forensics technique used by attackers to cover tracks. The correct response is to document the anomaly, continue gathering evidence to understand the scope, and then follow the organization's established incident response policy - this ensures legal and procedural integrity rather than escalating prematurely or taking unilateral action.

Concept tested: Incident response procedures and log integrity anomalies

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf

Topics

#incident response#log tampering#log analysis#security policy

Community Discussion

No community discussion yet for this question.

Full 312-50V10 Practice