312-50v11 Exam QuestionsBrowse all questions from this exam

312-50v11 Exam - Question 17


An incident investigator asks to receive a copy of the event logs from all firewalls, proxy servers, and Intrusion Detection Systems (IDS) on the network of an organization that has experienced a possible breach of security. When the investigator attempts to correlate the information in all of the logs, the sequence of many of the logged events do not match up.

What is the most likely cause?

Show Answer
Correct Answer: A

If the network devices are not all synchronized, the timestamps in the event logs from different devices will not match up correctly. This lack of synchronization can cause discrepancies in the sequence of events when the logs are correlated, even if all events are properly logged and unaltered. Synchronizing the clocks of all network devices using a protocol like NTP (Network Time Protocol) ensures that all logged events have consistent timestamps, allowing for accurate correlation and analysis.

Discussion

18 comments
Sign in to comment
Cytrail
Oct 9, 2022

The answer is A, no attack by an attacker was mentioned in the question. The question bordered on event logs only. Let's not be faster than the examiners...

MAAR1
Aug 27, 2024

it says this is an incident investigation. so there should be an attack. i guess the answer is C

awesomenessforso
Nov 24, 2024

The question states that the logs are in the wrong sequence, key word sequence. If the answer was C the logs would have been "missing"

awesomenessforso
Nov 24, 2024

The question states that the logs are in the wrong sequence, key word sequence. If the answer was C the logs would have been "missing"

callmetodd
Mar 20, 2023

the big keyword here is "many" of the logged events do not match up. If it was NTP, then all of the logs wouldn't match up. I'd suggest C as the correct answer. however, there is such a thing as the 'eccouncil box' and a "theme" that goes throughout the exam and course. which may suggest that A is the best "eccouncil" answer ;-)

Mr_Gray
Mar 25, 2023

this is a great call out. excellent point.

americaman80
Oct 7, 2022

Time synchronization is an important middleware service of distributed systems, amongst which Distributed Intrusion Detection System (DIDS) makes extensive use of time synchronization in particular.

smurphuk
Feb 23, 2023

The CEH course taught me that "an attacker may erase logs to avoid being caught". I'll be damned if the answer is not C?!? Time isnt even mentioned in the question.

Mr_Gray
Mar 19, 2023

the mention of synchronization can indicate the NTP is not set correctly. You do have validity to your point as if an attacker erased logs then they wouldn't match up later. This one merits additional research.

Re_My
May 25, 2023

I agreed, C is the rigth Answer acording to Infosec course. An Attacker may delete logs to erase trace.

GTofic
May 28, 2023

If the attacker erased the log there will be no correlation of the information. Answer is A, its about NTP (time) not synchronized

cerzocuspi
Oct 15, 2022

A is correct. Time sync

EngnSu
Dec 6, 2023

p.2874 Unsynchronized System Clocks can affect the working of automated tasks; The network administrator cannot accurately analyze the log files for any malicious activity, if the timestamps are mismatched

sam422
Sep 26, 2022

I go with C, an attacker can change time stamps to cover tracks

OleMadhatter
Oct 13, 2022

(A) time synchronization is off.

Daniel8660Option: A
Apr 14, 2024

Unsynchronized System Clocks fUnsynchronized System Clocks Timestamp inaccuracy constitutes the network administrator unable to analyze the log files for any malicious activity accurately. (P.2880/2864)

fishPSU21
Sep 5, 2022

if the company experienced a breach the correct answer should be C since the attacker most likely covered up their tracks

AndreasH
Sep 11, 2022

Wouldn't the attacker rather delete events completely from the logs instead of just changing the timeline? As I read the question the events are there, but the timeline is messed up (between devices), indicating a time sync problem.

fishPSU21
Sep 15, 2022

I can see that standpoint and get behind it.

fishPSU21
Sep 15, 2022

I can see that standpoint and get behind it.

sam422
Sep 27, 2022

If the assumption is Time Sync, then Answer A makes sense, however, it appears devices sync type, which makes answer C

dolumo
Nov 21, 2022

"the sequence of many of the logged events do not match up" C would have been correct if some events were not on some logs

selamkelamlar
Feb 4, 2023

i go with A.

Snipa_x
Feb 25, 2023

Answer will be A. If NTP is not utilized on all the logging servers then the event's will not correlate.

lawbut2
May 11, 2023

A is best answer. p2864 Unsynchronized System Clocks

K3nz0420
Jul 25, 2023

A is the ans

StormCloak4EverOption: A
Jan 5, 2024

The best answer is A.

vitusisyaOption: A
Dec 7, 2024

The time is not properly synchronized

asgasgOption: A
Dec 16, 2024

An attacker is expected to clear the logs. But this time, it is mismatch, not the lack of logs.