nerdexam
CompTIA

SY0-301 · Question #350

Ann, the security administrator, received a report from the security technician, that an unauthorized new user account was added to the server over two weeks ago. Which of the following could have…

The correct answer is A. Routine log audits. Routine log audits regularly review system and security logs, which would have detected the unauthorized account creation event far sooner than two weeks after it occurred.

Security operations

Question

Ann, the security administrator, received a report from the security technician, that an unauthorized new user account was added to the server over two weeks ago. Which of the following could have mitigated this event?

Options

  • ARoutine log audits
  • BJob rotation
  • CRisk likelihood assessment
  • DSeparation of duties

How the community answered

(47 responses)
  • A
    91% (43)
  • B
    2% (1)
  • C
    4% (2)
  • D
    2% (1)

Why each option

Routine log audits regularly review system and security logs, which would have detected the unauthorized account creation event far sooner than two weeks after it occurred.

ARoutine log auditsCorrect

Routine log audits involve regularly reviewing audit trails and event logs from servers to identify unauthorized changes such as new account creation. Had logs been reviewed on a routine schedule, the addition of the unauthorized account would have been discovered promptly rather than going undetected for two weeks. Log auditing is a core detective control recommended by NIST SP 800-92 for maintaining accountability and detecting insider threats or unauthorized access.

BJob rotation

Job rotation is an administrative control that reduces fraud risk over time by cycling employees through roles, but it would not have detected a specific unauthorized account creation event.

CRisk likelihood assessment

Risk likelihood assessment is a planning activity that evaluates the probability of threat events occurring and would not detect or alert on an actual unauthorized account addition.

DSeparation of duties

Separation of duties divides critical tasks among multiple individuals to prevent fraud but does not provide a mechanism for detecting unauthorized account creation after the fact.

Concept tested: Routine log auditing as a detective security control

Source: https://csrc.nist.gov/publications/detail/sp/800-92/final

Topics

#log auditing#account management#unauthorized access#monitoring

Community Discussion

No community discussion yet for this question.

Full SY0-301 Practice