nerdexam
EC-Council

EC0-350 · Question #458

A XYZ security System Administrator is reviewing the network system log files. He notes the following: Network log files are at 5 MB at 12:00 noon. At 14:00 hours, the log files at 3 MB What should…

The correct answer is B. He should log the event as suspicious activity, continue to investigate, and take further steps. See the full explanation below for the reasoning.

Question

A XYZ security System Administrator is reviewing the network system log files. He notes the following:

Network log files are at 5 MB at 12:00 noon. At 14:00 hours, the log files at 3 MB What should he assume has happened and what should he do about the situation?

Options

  • AHe should contact the attacker's ISP as soon as possible and have the connection disconnected.
  • BHe should log the event as suspicious activity, continue to investigate, and take further steps
  • CHe should log the file size, and archive the information, because the router crashed.
  • DHe should run a file system check, because the Syslog server has a self correcting file system problem.
  • EHe should disconnect from the Internet discontinue any further unauthorized use, because an

How the community answered

(43 responses)
  • A
    2% (1)
  • B
    79% (34)
  • C
    2% (1)
  • D
    9% (4)
  • E
    7% (3)

Community Discussion

No community discussion yet for this question.

Full EC0-350 Practice