PrepAway - Latest Free Exam Questions & Answers

Which of the following is the MOST likely reason why the incident response team is unable to identify and corr

The incident response team has received the following email messagE .
From: monitor@ext-company.com
To: security@company.com
Subject: Copyright infringement
A copyright infringement alert was triggered by IP address 13.10.66.5 at 09: 50: 01 GMT.
After reviewing the following web logs for IP 13.10.66.5, the team is unable to correlate and
identify the incident.
09: 45: 33 13.10.66.5 http: //remote.site.com/login.asp?user=john
09: 50: 22 13.10.66.5 http: //remote.site.com/logout.asp?user=anne
10: 50: 01 13.10.66.5 http: //remote.site.com/access.asp?file=movie.mov
11: 02: 45 13.10.65.5 http: //remote.site.com/download.asp?movie.mov=ok
Which of the following is the MOST likely reason why the incident response team is unable
to identify and correlate the incident?

PrepAway - Latest Free Exam Questions & Answers

A.
The logs are corrupt and no longer forensically sound.

B.
Traffic logs for the incident are unavailable.

C.
Chain of custody was not properly maintained.

D.
Incident time offsets were not accounted for.


Leave a Reply