Acme Corporation is doing a core evaluation of its centralized logging capabilities. Which of the following scenarios indicates a failure in more than one CIS Control?
I'm going to have to go with C on this one. The loghost time being out-of-sync with an external host? That's just begging for all kinds of timestamp-related issues. Plus, it's an easy fix - just sync those clocks!
D all the way! Undocumented servers? That's a recipe for disaster. Probably violates like half the CIS Controls. Though I do wonder - how does the loghost even know these servers are undocumented? Maybe the IT team just forgot to update the inventory.
Hmm, I'm going to go with B. Receiving logs from hosts with different timezone values could be a sign of poor Centralized Log Management. At least it's not as bad as having a loghost completely missing logs, that's just sloppy.
C seems like the obvious choice here. If the loghost time is out-of-sync with an external host, that could indicate a failure in Audit Log Management and Continuous Vulnerability Management.
I think the answer is D. Having logs from undocumented servers is definitely a failure in multiple CIS Controls, like Inventory and Control of Enterprise Assets and Secure Configuration of Enterprise Assets and Software.
Gerald
15 days agoAriel
16 days agoCeola
17 days agoAntione
22 days agoElenore
11 days agoJoye
1 months agoAlisha
5 days agoClaudia
12 days agoDortha
14 days agoJennie
1 months agoEllen
2 months ago