A. administrator thinks the UNIX systems may be compromised, but a review of system log files provides no useful information. After discussing the situation with the security team, the administrator suspects that the attacker may be altering the log files and removing evidence of intrusion activity. Which of the following actions will help detect attacker attempts to further alter log files?

🎲 Try a Random Question  |  Total Questions in Quiz: 179  |  🧠 Study this quiz with Flashcards
This question is part of a full practice quiz:
SY0-501 CompTIA Security+ Certification Exam - Practice Test 2 — practice the complete quiz, review flashcards, or try a random question.


A. administrator thinks the UNIX systems may be compromised, but a review of system log files provides no useful information. After discussing the situation with the security team, the administrator suspects that the attacker may be altering the log files and removing evidence of intrusion activity. Which of the following actions will help detect attacker attempts to further alter log files?