nerdexam
CompTIA

SY0-501 · Question #310

A company is investigating a data compromise where data exfiltration occurred. Prior to the investigation, the supervisor terminates an employee as a result of the suspected data loss. During the…

The correct answer is B. Log failure. The investigation into data exfiltration was severely hampered by the inability to retrieve sufficient evidence from the role-based authentication system, directly indicating a critical deficiency in logging capabilities. This highlights the importance of robust logging for…

Submitted by dimitri_ru· Mar 4, 2026Security operations

Question

A company is investigating a data compromise where data exfiltration occurred. Prior to the investigation, the supervisor terminates an employee as a result of the suspected data loss. During the investigation, the supervisor is absent for the interview, and little evidence can be provided form the role-based authentication system in use by the company. The situation can be identified for future mitigation as which of the following?

Options

  • AJob rotation
  • BLog failure
  • CLack of training
  • DInsider threat

How the community answered

(39 responses)
  • A
    8% (3)
  • B
    74% (29)
  • C
    5% (2)
  • D
    13% (5)

Why each option

The investigation into data exfiltration was severely hampered by the inability to retrieve sufficient evidence from the role-based authentication system, directly indicating a critical deficiency in logging capabilities. This highlights the importance of robust logging for effective forensic analysis and future incident mitigation.

AJob rotation

Job rotation is a preventative administrative control designed to mitigate insider threats and fraud, but it does not directly explain the technical inability to retrieve evidence from an authentication system.

BLog failureCorrect

The statement 'little evidence can be provided form the role-based authentication system' explicitly points to a failure in the organization's logging capabilities. Robust logging is essential for capturing authentication events, access attempts, and system activities, which are critical for providing forensic evidence during a data compromise investigation. Without proper log collection, retention, and accessibility, effective incident response and root cause analysis are severely hindered.

CLack of training

While lack of training can lead to various security weaknesses, it does not specifically account for the technical failure of an authentication system to provide evidence through its logs.

DInsider threat

An insider threat might be the cause of the data exfiltration itself, but it does not describe the specific issue of the investigation being hindered by a lack of available system evidence.

Concept tested: Importance of security logging for incident response and forensic analysis

Source: https://learn.microsoft.com/en-us/training/modules/design-logging-auditing-strategy/

Topics

#log management#incident investigation#audit logging#data exfiltration

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice