nerdexam
EC-Council

312-50V9 · Question #54

A company has hired a security administrator to maintain and administer Linux and Windows- based systems. Written in the nightly report file is the following: - Firewall log files are at the…

The correct answer is D. Log the event as suspicious activity, continue to investigate, and act according to the site's. Firewall log files that decrease in size over time are a strong indicator of log tampering and should be treated as suspicious activity requiring investigation guided by the site's incident response policy.

Malware Threats

Question

A company has hired a security administrator to maintain and administer Linux and Windows- based systems. Written in the nightly report file is the following:

  • Firewall log files are at the expected value of 4 MB.
  • The current time is 12am. Exactly two hours later the size has

decreased considerably.

  • Another hour goes by and the log files have shrunk in size again.

Which of the following actions should the security administrator take?

Options

  • ALog the event as suspicious activity and report this behavior to the incident response team
  • BLog the event as suspicious activity, call a manager, and report this as soon as possible.
  • CRun an anti-virus scan because it is likely the system is infected by malware.
  • DLog the event as suspicious activity, continue to investigate, and act according to the site's

How the community answered

(56 responses)
  • A
    13% (7)
  • B
    25% (14)
  • C
    7% (4)
  • D
    55% (31)

Why each option

Firewall log files that decrease in size over time are a strong indicator of log tampering and should be treated as suspicious activity requiring investigation guided by the site's incident response policy.

ALog the event as suspicious activity and report this behavior to the incident response team

Immediately escalating to the incident response team without further investigation is premature and bypasses the administrator's responsibility to collect additional context before escalating.

BLog the event as suspicious activity, call a manager, and report this as soon as possible.

Calling a manager as an ad hoc action skips the structured escalation and documentation steps defined in the site's incident response policy, which should govern all such decisions.

CRun an anti-virus scan because it is likely the system is infected by malware.

Running an antivirus scan addresses only one narrow cause and does not investigate the primary concern of deliberate log file tampering, which requires a broader forensic approach.

DLog the event as suspicious activity, continue to investigate, and act according to the site'sCorrect

Log files grow monotonically under normal operation, so a decrease in size is a clear anomaly that suggests an attacker may be clearing or modifying logs to conceal malicious activity. The correct response is to document the observation as suspicious, continue gathering information to understand the scope and timeline of the anomaly, and then follow the organization's established incident response policy for consistent, legally defensible handling. Acting according to site policy ensures the right escalation paths and preservation steps are followed.

Concept tested: Log tampering detection and incident response policy adherence

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf

Topics

#log file tampering#incident response#suspicious activity#log shrinkage

Community Discussion

No community discussion yet for this question.

Full 312-50V9 Practice