312-50V9 · Question #54
A company has hired a security administrator to maintain and administer Linux and Windows- based systems. Written in the nightly report file is the following: - Firewall log files are at the…
The correct answer is D. Log the event as suspicious activity, continue to investigate, and act according to the site's. Firewall log files that decrease in size over time are a strong indicator of log tampering and should be treated as suspicious activity requiring investigation guided by the site's incident response policy.
Question
A company has hired a security administrator to maintain and administer Linux and Windows- based systems. Written in the nightly report file is the following:
- Firewall log files are at the expected value of 4 MB.
- The current time is 12am. Exactly two hours later the size has
decreased considerably.
- Another hour goes by and the log files have shrunk in size again.
Which of the following actions should the security administrator take?
Options
- ALog the event as suspicious activity and report this behavior to the incident response team
- BLog the event as suspicious activity, call a manager, and report this as soon as possible.
- CRun an anti-virus scan because it is likely the system is infected by malware.
- DLog the event as suspicious activity, continue to investigate, and act according to the site's
How the community answered
(56 responses)- A13% (7)
- B25% (14)
- C7% (4)
- D55% (31)
Why each option
Firewall log files that decrease in size over time are a strong indicator of log tampering and should be treated as suspicious activity requiring investigation guided by the site's incident response policy.
Immediately escalating to the incident response team without further investigation is premature and bypasses the administrator's responsibility to collect additional context before escalating.
Calling a manager as an ad hoc action skips the structured escalation and documentation steps defined in the site's incident response policy, which should govern all such decisions.
Running an antivirus scan addresses only one narrow cause and does not investigate the primary concern of deliberate log file tampering, which requires a broader forensic approach.
Log files grow monotonically under normal operation, so a decrease in size is a clear anomaly that suggests an attacker may be clearing or modifying logs to conceal malicious activity. The correct response is to document the observation as suspicious, continue gathering information to understand the scope and timeline of the anomaly, and then follow the organization's established incident response policy for consistent, legally defensible handling. Acting according to site policy ensures the right escalation paths and preservation steps are followed.
Concept tested: Log tampering detection and incident response policy adherence
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf
Topics
Community Discussion
No community discussion yet for this question.