CAS-002 · Question #177
An organization did not know its internal customer and financial databases were compromised until the attacker published sensitive portions of the database on several popular attacker websites. The…
The correct answer is D. Insufficient logging and mechanisms for review. Without sufficient logging and log review mechanisms, the organization had no forensic evidence trail to reconstruct the timeline, attack vector, or identity of the attacker after a database compromise.
Question
An organization did not know its internal customer and financial databases were compromised until the attacker published sensitive portions of the database on several popular attacker websites. The organization was unable to determine when, how, or who conducted the attacks but rebuilt, restored, and updated the compromised database server to continue operations. Which of the following is MOST likely the cause for the organization's inability to determine what really occurred?
Options
- AToo few layers of protection between the Internet and internal network
- BLack of a defined security auditing methodology
- CPoor intrusion prevention system placement and maintenance
- DInsufficient logging and mechanisms for review
How the community answered
(47 responses)- A13% (6)
- B4% (2)
- C4% (2)
- D79% (37)
Why each option
Without sufficient logging and log review mechanisms, the organization had no forensic evidence trail to reconstruct the timeline, attack vector, or identity of the attacker after a database compromise.
Insufficient network segmentation may have contributed to access, but the specific inability to determine what occurred points to a logging gap rather than a perimeter architecture weakness.
A lack of a defined security auditing methodology is a governance issue broader than the specific technical gap - inability to reconstruct events points directly to missing log data.
Poor IPS placement and maintenance relates to attack prevention, not to the post-incident inability to determine attribution and timeline, which is a logging and forensics problem.
Comprehensive logging across database servers, network devices, and application layers is the foundation of forensic investigation capability, providing the evidence needed to reconstruct events. When logging is insufficient or absent, there is no data to determine when access occurred, which accounts or vectors were used, or what data was exfiltrated. Regular log review and alerting mechanisms such as a SIEM would also have enabled earlier detection rather than discovering the breach only after the attacker published stolen data.
Concept tested: Logging and audit trails for forensic investigation capability
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-92.pdf
Topics
Community Discussion
No community discussion yet for this question.