CAS-003 · Question #794
Ann, a CIRT member, is conducting incident response activities on a network that consists of several hundred virtual servers and thousands of endpoints and users. The network generates more than…
The correct answer is B. Log reduction and visualization tools. With over 10,000 log messages per second across hundreds of virtual servers and thousands of endpoints, manually reviewing raw logs is infeasible. Log reduction and visualization tools (such as SIEM dashboards, log aggregators with filtering, and timeline visualizations) allow…
Question
Ann, a CIRT member, is conducting incident response activities on a network that consists of several hundred virtual servers and thousands of endpoints and users. The network generates more than 10,000 log messages per second. The enterprise belong to a large, web-based cryptocurrency startup, Ann has distilled the relevant information into an easily digestible report for executive management . However, she still needs to collect evidence of the intrusion that caused the incident. Which of the following should Ann use to gather the required information?
Options
- ATraffic interceptor log analysis
- BLog reduction and visualization tools
- CProof of work analysis
- DLedger analysis software
How the community answered
(41 responses)- A2% (1)
- B83% (34)
- C10% (4)
- D5% (2)
Explanation
With over 10,000 log messages per second across hundreds of virtual servers and thousands of endpoints, manually reviewing raw logs is infeasible. Log reduction and visualization tools (such as SIEM dashboards, log aggregators with filtering, and timeline visualizations) allow an analyst to filter noise, correlate events across systems, identify anomalous patterns, and pinpoint the specific log entries relevant to the intrusion. These tools transform massive, unstructured log volumes into actionable forensic evidence. Traffic interceptor analysis (A) is useful for capturing live traffic but does not address historical log evidence. Proof of work (C) and ledger analysis (D) are blockchain-related concepts irrelevant to traditional enterprise incident response.
Topics
Community Discussion
No community discussion yet for this question.