ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 582 - SY0-601 discussion

Report
Export

A privileged user at a company stole several proprietary documents from a server. The user also went into the log files and deleted all records of the incident The systems administrator has just informed investigators that other log files are available for review Which of the following did the administrator most likely configure that will assist the investigators?

A.
Memory dumps
Answers
A.
Memory dumps
B.
The syslog server
Answers
B.
The syslog server
C.
The application logs
Answers
C.
The application logs
D.
The log retention policy
Answers
D.
The log retention policy
Suggested answer: B

Explanation:

A syslog server is a centralized log management system that collects, stores, and manages syslog messages generated by various network devices, servers, applications, and other sources. A syslog server can assist the investigators in this case because it can provide an alternative source of log files that may contain evidence of the incident. The privileged user may have deleted the local log files on the server, but not the remote log files on the syslog server. Therefore, the investigators can access the syslog server and analyze the log messages related to the user's activities and actions

asked 02/10/2024
aakriti grover
51 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first