🌍 All Study Guides📊 Dashboard📰 Blog💡 About
Google Cybersecurity Professional Certificate • STUDY MODE

OVERVIEW OF LOGS

QUESTION 1 OF 4

What is the primary purpose of logs during incident investigation?

A
To identify and diagnose system issues
B
To manage alert volumes
C
To provide a record of event detailsCorrect Answer
D
To improve user experience
Explanation:

The primary purpose of logs during incident investigation is to provide a record of event details. Knowing what occurred on systems, networks, and devices helps security analysts identify unusual or malicious activity.

QUESTION 2 OF 4

A security analyst wants to determine whether a suspicious login was successful. Which log type would be most useful for this purpose?

A
Firewall
B
System
C
AuthenticationCorrect Answer
D
Network
Explanation:

An authentication log would be most useful for this purpose. Authentication logs record login attempts, including whether a login was successful.

QUESTION 3 OF 4

In the following log, what action does the log entry record? [ALLOW: wikipedia.org] Source: 192.167.1.1 Friday, 10 June 2022 11:36:12

A
Friday, 10 June 2022 11:36:12
B
Source
C
192.167.1.1
D
ALLOWCorrect Answer
Explanation:

ALLOW refers to the action that has been recorded. In this instance, it allows access to wikipedia.org.

QUESTION 4 OF 4

Fill in the blank: _____ is the process of examining logs to identify events of interest.

A
Log forwarder
B
Log file
C
Logging
D
Log analysisCorrect Answer
Explanation:

Log analysis is the process of examining logs to identify events of interest.

Ready to test your recall?

What is the primary purpose of logs during incident investigation?

A
To identify and diagnose system issues
B
To manage alert volumes
C
To provide a record of event details
D
To improve user experience

How confident are you in this answer?