II0-001 · Question #228
Which of the following are important to the investigator regarding logging:
The correct answer is D. All of the above. D is correct because all three factors are equally critical to a forensic investigator - none can be dismissed when conducting a thorough log-based investigation. A (Logging methods) matters because how logs are generated determines their integrity, format, and trustworthiness…
Question
Which of the following are important to the investigator regarding logging:
Options
- AThe logging methods
- BLog retention
- CLocation of stored logs
- DAll of the above
How the community answered
(15 responses)- A7% (1)
- B7% (1)
- C13% (2)
- D73% (11)
Explanation
D is correct because all three factors are equally critical to a forensic investigator - none can be dismissed when conducting a thorough log-based investigation.
- A (Logging methods) matters because how logs are generated determines their integrity, format, and trustworthiness as evidence. Centralized syslog vs. local file logging vs. SIEM ingestion each have different implications for tampering and completeness.
- B (Log retention) is essential because logs that have been overwritten or purged before an investigation begins are simply unavailable - a 7-day retention window is useless if an incident occurred 30 days ago.
- C (Location of stored logs) is critical because logs stored on the compromised system itself may have been altered by an attacker, whereas off-system or write-once storage provides stronger evidentiary value.
Memory tip: Think of logs as a crime scene - you need to know how evidence was collected (methods), whether it still exists (retention), and where it's being kept and whether it could be contaminated (location). All three or the scene is compromised.
Community Discussion
No community discussion yet for this question.