exam questions

Exam Lead Implementer All Questions

View all questions & answers for the Lead Implementer exam

Exam Lead Implementer topic 1 question 18 discussion

Actual exam question from PECB's Lead Implementer
Question #: 18
Topic #: 1
[All Lead Implementer Questions]

Can Socket Inc. find out that no persistent backdoor was placed and that the attack was initiated from an employee inside the company by reviewing event logs that record user faults and exceptions? Refer to scenario 3.

  • A. Yes, Socket Inc. can find out that no persistent backdoor was placed by only reviewing user faults and exceptions logs
  • B. No, Socket Inc. should also have reviewed event logs that record user activities
  • C. No, Socket Inc. should have reviewed all the logs on the syslog server
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Acrisius
2 months, 1 week ago
Selected Answer: C
The answer here is C 8.15 Logging A detective control To record events, generate evidence, ensure the integrity of log information, prevent against unauthorized access, identify information security events that can lad to an information security incident and to support investigation Logs support investigations Socket examined only two logs when it should examine all. So what people are doing, login and out etc
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago