SY0-301 · Question #350
Ann, the security administrator, received a report from the security technician, that an unauthorized new user account was added to the server over two weeks ago. Which of the following could have…
The correct answer is A. Routine log audits. Routine log audits regularly review system and security logs, which would have detected the unauthorized account creation event far sooner than two weeks after it occurred.
Question
Ann, the security administrator, received a report from the security technician, that an unauthorized new user account was added to the server over two weeks ago. Which of the following could have mitigated this event?
Options
- ARoutine log audits
- BJob rotation
- CRisk likelihood assessment
- DSeparation of duties
How the community answered
(47 responses)- A91% (43)
- B2% (1)
- C4% (2)
- D2% (1)
Why each option
Routine log audits regularly review system and security logs, which would have detected the unauthorized account creation event far sooner than two weeks after it occurred.
Routine log audits involve regularly reviewing audit trails and event logs from servers to identify unauthorized changes such as new account creation. Had logs been reviewed on a routine schedule, the addition of the unauthorized account would have been discovered promptly rather than going undetected for two weeks. Log auditing is a core detective control recommended by NIST SP 800-92 for maintaining accountability and detecting insider threats or unauthorized access.
Job rotation is an administrative control that reduces fraud risk over time by cycling employees through roles, but it would not have detected a specific unauthorized account creation event.
Risk likelihood assessment is a planning activity that evaluates the probability of threat events occurring and would not detect or alert on an actual unauthorized account addition.
Separation of duties divides critical tasks among multiple individuals to prevent fraud but does not provide a mechanism for detecting unauthorized account creation after the fact.
Concept tested: Routine log auditing as a detective security control
Source: https://csrc.nist.gov/publications/detail/sp/800-92/final
Topics
Community Discussion
No community discussion yet for this question.