The primary purpose of logs during incident investigation is to provide a record of event details. Knowing what occurred on systems, networks, and devices helps security analysts identify unusual or malicious activity.
An authentication log would be most useful for this purpose. Authentication logs record login attempts, including whether a login was successful.
ALLOW refers to the action that has been recorded. In this instance, it allows access to wikipedia.org.
Log analysis is the process of examining logs to identify events of interest.
What is the primary purpose of logs during incident investigation?
How confident are you in this answer?