CAS-001 · Question #294
An organization did not know its internal customer and financial databases were compromised until the attacker published sensitive portions of the database on several popular attacker websites. The…
The correct answer is D. Insufficient logging and mechanisms for review. The inability to determine when, how, or who conducted the attack is a forensic/investigative failure, not a prevention failure. Without sufficient logging (e.g., database query logs, authentication logs, network flow records) and without a process to regularly review those…
Question
An organization did not know its internal customer and financial databases were compromised until the attacker published sensitive portions of the database on several popular attacker websites. The organization was unable to determine when, how, or who conducted the attacks but rebuilt, restored, and updated the compromised database server to continue operations. Which of the following is MOST likely the cause for the organization's inability to determine what really occurred?
Options
- AToo few layers of protection between the Internet and internal network
- BLack of a defined security auditing methodology
- CPoor intrusion prevention system placement and maintenance
- DInsufficient logging and mechanisms for review
How the community answered
(32 responses)- A9% (3)
- B6% (2)
- C16% (5)
- D69% (22)
Explanation
The inability to determine when, how, or who conducted the attack is a forensic/investigative failure, not a prevention failure. Without sufficient logging (e.g., database query logs, authentication logs, network flow records) and without a process to regularly review those logs, there is no audit trail to reconstruct the timeline of events. Option A (too few layers of protection) explains how the attacker got in, not why the organization could not reconstruct events afterward. Option B (lack of auditing methodology) is related but insufficient logging is the root technical cause. Option C (poor IPS placement) is also about prevention, not forensic reconstruction. Comprehensive logging with regular review is the foundational requirement for any post-incident investigation.
Topics
Community Discussion
No community discussion yet for this question.