After a recent ransomware attack on a companys system an adm - CompTIA Security+ SY0-701

Question

After a recent ransomware attack on a company's system, an administrator reviewed the log files. Which of the following control types did the administrator use?

Answers
  1. correct
Explanation

Correct Answer: B. Detective

By reviewing the log files after a ransomware attack, the administrator is using a detective control. Detective controls are designed to identify and record potential security incidents, enabling administrators to analyze what happened and potentially trace the source of the issue. Log files are a common example of detective controls, as they help monitor and detect events post-occurrence.

Explanations for Incorrect Options:

  • Compensating:
    Compensating controls are alternative measures implemented when primary controls are not feasible. For example, if multi-factor authentication isn't available, a compensating control might involve strict monitoring. Reviewing log files after an attack does not fit this category.

  • Preventive:
    Preventive controls are implemented to stop an attack before it occurs (e.g., firewalls, anti-malware software, or access controls). Reviewing log files after an attack is a reactive process, not a preventive measure, so this is incorrect.

  • Corrective:
    Corrective controls are applied after an incident to restore systems to normal operation (e.g., restoring from backups or patching vulnerabilities). While reviewing logs helps analyze the attack, it does not directly correct or restore the system, so this is not the correct answer.

No Payment Cards Needed

Related Courses

Discover a range of courses designed to provide you with the knowledge and skills needed to excel in your chosen field.

a prepsaret exam featured image
CompTIA Prep

220-1201 - CompTIA A+ Exam Core 1

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

220-1202 - CompTIA A+ Exam Core 2

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA SecurityX CAS-005

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Cloud Essentials+ CLO-002

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Network+ N10-009

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Data + DA0-001

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Pentest+

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Linux+ XK0-005

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA CySA+ CSO-003

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA DataSys+ DS0-001

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Tech+ FC0-U71

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Cloud+ CV0-004

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Server+ SK0-005

Start Course Prep

Easy way to pass your test within a week with prepsaret

You don’t need one month to study and pass your test.
With Prepsaret, it takes you a few days to grasp all the concepts needed to pass your exams

View Courses Offered