What is the most likely cause?

Posted by: Pdfprep Category: 312-50v9 Tags: , ,

An incident investigator asks to receive a copy of the event from all firewalls, proxy servers, and Intrusion Detection Systems (IDS) on the network of an organization that has experienced a possible breach of security. When the investigator attempts to correlate the information in all of the logs the sequence of many of the logged events do not match up.

What is the most likely cause?
A . The network devices are not all synchronized
B . The security breach was a false positive.
C . The attack altered or erased events from the logs.
D . Proper chain of custody was not observed while collecting the logs.

Answer: C

Leave a Reply

Your email address will not be published.