After a recent ransomware attack on a company's system, an administrator reviewed the log files. Which of the following control types did the administrator use?
Detective controls are used to identify and respond to security incidents like ransomware attacks.
Detective controls are designed to detect and alert administrators about security breaches or anomalies after they occur. In the scenario presented, the administrator reviewed log files, which is a method of monitoring and identifying unauthorized access or malicious activity.
Compensating controls are alternative measures implemented to satisfy security requirements when primary controls cannot be used. They do not actively detect security incidents but rather provide a workaround to mitigate risks. In this case, reviewing log files does not align with the definition of compensating controls, as it directly relates to identifying security issues rather than providing an alternative measure.
Detective controls, such as log file reviews, are specifically intended to identify and alert on security events and incidents. By analyzing log files, the administrator can detect unauthorized access or other suspicious activities that occurred, making this the correct choice.
Preventive controls are designed to stop security incidents before they occur, such as firewalls or access controls. While these controls are essential for overall security posture, they do not involve the review of log files for identifying past incidents. Hence, this choice does not accurately represent the action taken by the administrator.
Corrective controls are actions taken to address security incidents after they have been detected, aiming to restore systems or mitigate damage. While reviewing logs is part of the incident response process, it does not fall under corrective controls since it focuses on detection rather than remediation.
In cybersecurity, the distinction between control types is crucial for effective incident management. Detective controls, such as log file reviews, play an essential role in identifying and responding to incidents like ransomware attacks. Understanding these control types enhances an organization's ability to manage security risks and respond effectively to threats.
Related Questions
View allAn important patch for a critical application has just been released,...
Which of the following is a type of vulnerability for which no patch c...
A remote employee navigates to a shopping website on their company-own...
A security officer observes that a software development team is not co...
Which of the following describes the procedures a penetration tester m...
Related Quizzes
View allCompTIA A Plus Certification Exam
CompTIA A Plus Exam Questions
CompTIA A Plus 1001 Exams Practice
CompTIA A Plus Practice Exam
CompTIA CySA+ Cybersecurity Analyst Certification all in One Exam Guide
CompTIA Network Plus Certification Exam Quiz
CompTIA Security Plus Exam Answers
Free CompTIA Security Plus Practice Test
CompTIA Security Plus Simulation Questions
CompTIA Security Plus Example Questions
- ✓ 500+ Practice Questions
- ✓ Detailed Explanations
- ✓ Progress Analytics
- ✓ Exam Simulations