ExamGecko
Question list
Search
Search

Related questions











Question 109 - 200-201 discussion

Report
Export

An offline audit log contains the source IP address of a session suspected to have exploited a vulnerability resulting in system compromise.

Which kind of evidence is this IP address?

A.

best evidence

Answers
A.

best evidence

B.

corroborative evidence

Answers
B.

corroborative evidence

C.

indirect evidence

Answers
C.

indirect evidence

D.

forensic evidence

Answers
D.

forensic evidence

Suggested answer: B

Explanation:

The source IP address from an audit log that indicates a session which may have exploited a vulnerability is consideredcorroborative evidence. This type of evidence supports other evidence that suggests a security breach occurred. In the context of cybersecurity, corroborative evidence can help establish that an attack was carried out and can be used in conjunction with other data points to build a case during an investigation.

asked 07/10/2024
jim eagleton
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first