Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam 712-50 All Questions

View all questions & answers for the 712-50 exam

Exam 712-50 topic 1 question 399 discussion

Actual exam question from ECCouncil's 712-50
Question #: 399
Topic #: 1
[All 712-50 Questions]

Which of the following would negatively impact a log analysis of a multinational organization?

  • A. Centralized log management
  • B. Encrypted log files in transit
  • C. Each node set to local time
  • D. Log aggregation agent each node
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
alfaMegatron
3 months, 1 week ago
Selected Answer: C
In context of the question the answer is C.
upvoted 1 times
...
johndoe69
4 months, 1 week ago
Selected Answer: C
NIST Special Publication 800-92: Guide to Computer Security Log Management "When the clocks on systems are not synchronized, event correlation can become very difficult, and events from one system may appear to have occurred before they actually did, relative to the time on another system. It is strongly recommended that organizations use a common time synchronization protocol, such as Network Time Protocol (NTP), to ensure that the clocks on all systems are synchronized."
upvoted 1 times
...
arifbhatkar
1 year, 4 months ago
Selected Answer: C
he correct answer is C. Each node set to local time. Setting each node to local time would negatively impact a log analysis of a multinational organization. In order to perform effective log analysis, it is important to have consistent and standardized timestamps across all log entries. If each node within the organization is set to local time, it would introduce inconsistencies in the timestamps recorded in the log files, making it difficult to correlate events accurately and perform accurate analysis across different systems and regions.
upvoted 2 times
...
Pika26
1 year, 8 months ago
Answer is C.
upvoted 2 times
...
LARdT
2 years, 7 months ago
A. Would be beneficial B. Would be a necessary good practice C. Is not good, makes correlation difficult. This would be the forensic answer. D This can be argued to be the worst as information is lost in the aggregation. You would have to resort to the unaggregated logs to investigate an incident.
upvoted 3 times
...
vmathan
3 years ago
I also have the same concern about local time, But still the log analysis will not be delayed but this cause mapping the chronology of event. But if the local aggregation is done, then we need to analyse each log which will cause delay
upvoted 1 times
...
Rufus1
3 years, 1 month ago
I reconsider the question. Is D the correct answer
upvoted 1 times
...
Rufus1
3 years, 1 month ago
Should be "C"... Why is local aggregation the correct answer ?
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...