ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 282 - CS0-003 discussion

Report
Export

A laptop that is company owned and managed is suspected to have malware. The company implemented centralized security logging. Which of the following log sources will confirm the malware infection?

A.
XDR logs
Answers
A.
XDR logs
B.
Firewall logs
Answers
B.
Firewall logs
C.
IDS logs
Answers
C.
IDS logs
D.
MFA logs
Answers
D.
MFA logs
Suggested answer: A

Explanation:

XDR logs will confirm the malware infection because XDR is a system that collects and analyzes data from multiple sources, such as endpoints, networks, cloud applications, and email security, to detect and respond to advanced threats12. XDR can provide a comprehensive view of the attack chain and the context of the malware infection. Firewall logs, IDS logs, and MFA logs are not sufficient to confirm the malware infection, as they only provide partial or indirect information about the network traffic, intrusion attempts, or user authentication.

Reference: Cybersecurity Analyst+ - CompTIA, XDR: definition and benefits for MSPs| WatchGuard Blog, Extended detection and response - Wikipedia

asked 02/10/2024
Harshvir Bhati
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first