SSCP · Question #370
Which of the following is most likely to be useful in detecting intrusions?
The correct answer is C. Audit trails. Audit trails (logs) record a chronological history of system events - logins, file accesses, privilege use, configuration changes - which can be reviewed in real time or after the fact to detect anomalous or unauthorized activity indicative of an intrusion. Access control lists…
Question
Which of the following is most likely to be useful in detecting intrusions?
Options
- AAccess control lists
- BSecurity labels
- CAudit trails
- DInformation security policies
How the community answered
(16 responses)- B6% (1)
- C88% (14)
- D6% (1)
Explanation
Audit trails (logs) record a chronological history of system events - logins, file accesses, privilege use, configuration changes - which can be reviewed in real time or after the fact to detect anomalous or unauthorized activity indicative of an intrusion. Access control lists (A) and security labels (B) are preventive controls that enforce policy but do not detect intrusions. Information security policies (D) define rules but have no detection capability. Audit trails are the foundational detective control for intrusion detection and forensic analysis.
Topics
Community Discussion
No community discussion yet for this question.