nerdexam
(ISC)2

SSCP · Question #370

Which of the following is most likely to be useful in detecting intrusions?

The correct answer is C. Audit trails. Audit trails (logs) record a chronological history of system events - logins, file accesses, privilege use, configuration changes - which can be reviewed in real time or after the fact to detect anomalous or unauthorized activity indicative of an intrusion. Access control lists…

Submitted by emma.c· Apr 18, 2026Risk Identification, Monitoring and Analysis

Question

Which of the following is most likely to be useful in detecting intrusions?

Options

  • AAccess control lists
  • BSecurity labels
  • CAudit trails
  • DInformation security policies

How the community answered

(16 responses)
  • B
    6% (1)
  • C
    88% (14)
  • D
    6% (1)

Explanation

Audit trails (logs) record a chronological history of system events - logins, file accesses, privilege use, configuration changes - which can be reviewed in real time or after the fact to detect anomalous or unauthorized activity indicative of an intrusion. Access control lists (A) and security labels (B) are preventive controls that enforce policy but do not detect intrusions. Information security policies (D) define rules but have no detection capability. Audit trails are the foundational detective control for intrusion detection and forensic analysis.

Topics

#Intrusion Detection#Audit Trails#Security Monitoring#Detection Controls

Community Discussion

No community discussion yet for this question.

Full SSCP Practice