Which of the following log elements is NOT typically included to support investigations?

Prepare for the DSAC-11 Annex B Test. Study with our quiz featuring flashcards and multiple-choice questions, each question accompanied by hints and explanations. Get ready to excel!

Multiple Choice

Which of the following log elements is NOT typically included to support investigations?

Explanation:
Focusing on what helps investigations reconstruct what happened, logs typically capture when an event occurred, what kind of event it was, and who performed it. A timestamp lets you sequence actions and align events across systems. The event type clarifies what happened, such as login, file access, or error. A user ID identifies the actor responsible for the action, which is essential for accountability and tracing. The physical location of the server is not normally included in log records because it doesn’t directly show the sequence, nature, or actor of a given event. Location might be inferred from network data like IPs or DNS, but storing a server’s geographic location is not a standard, reliable log attribute for investigations and can raise privacy concerns.

Focusing on what helps investigations reconstruct what happened, logs typically capture when an event occurred, what kind of event it was, and who performed it. A timestamp lets you sequence actions and align events across systems. The event type clarifies what happened, such as login, file access, or error. A user ID identifies the actor responsible for the action, which is essential for accountability and tracing.

The physical location of the server is not normally included in log records because it doesn’t directly show the sequence, nature, or actor of a given event. Location might be inferred from network data like IPs or DNS, but storing a server’s geographic location is not a standard, reliable log attribute for investigations and can raise privacy concerns.

Subscribe

Get the latest from Passetra

You can unsubscribe at any time. Read our privacy policy