Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

GIAC Exam GCCC Topic 1 Question 62 Discussion

Actual exam question for GIAC's GCCC exam
Question #: 62
Topic #: 1
[All GCCC Questions]

Acme Corporation is doing a core evaluation of its centralized logging capabilities. Which of the following scenarios indicates a failure in more than one CIS Control?

Show Suggested Answer Hide Answer
Suggested Answer: D

Contribute your Thoughts:

Gerald
2 months ago
I'm going to have to go with C on this one. The loghost time being out-of-sync with an external host? That's just begging for all kinds of timestamp-related issues. Plus, it's an easy fix - just sync those clocks!
upvoted 0 times
...
Ariel
2 months ago
D all the way! Undocumented servers? That's a recipe for disaster. Probably violates like half the CIS Controls. Though I do wonder - how does the loghost even know these servers are undocumented? Maybe the IT team just forgot to update the inventory.
upvoted 0 times
Denny
26 days ago
B) The loghost is receiving logs from hosts with different timezone values
upvoted 0 times
...
Fernanda
28 days ago
D) The loghost is receiving out-of-sync logs from undocumented servers
upvoted 0 times
...
Jenise
1 months ago
A) The loghost is missing logs from 3 servers in the inventory
upvoted 0 times
...
...
Ceola
2 months ago
Hmm, I'm going to go with B. Receiving logs from hosts with different timezone values could be a sign of poor Centralized Log Management. At least it's not as bad as having a loghost completely missing logs, that's just sloppy.
upvoted 0 times
...
Antione
2 months ago
C seems like the obvious choice here. If the loghost time is out-of-sync with an external host, that could indicate a failure in Audit Log Management and Continuous Vulnerability Management.
upvoted 0 times
Nieves
1 months ago
C is definitely a red flag for Audit Log Management and Continuous Vulnerability Management.
upvoted 0 times
...
Marjory
1 months ago
D could indicate a failure in Boundary Defense and Data Protection.
upvoted 0 times
...
Aliza
1 months ago
B might be a failure in Secure Configuration Management as well.
upvoted 0 times
...
Elenore
2 months ago
I think A could also indicate a failure in Secure Configuration Management.
upvoted 0 times
...
...
Joye
3 months ago
I think the answer is D. Having logs from undocumented servers is definitely a failure in multiple CIS Controls, like Inventory and Control of Enterprise Assets and Secure Configuration of Enterprise Assets and Software.
upvoted 0 times
Alisha
2 months ago
The loghost receiving logs from hosts with different timezone values could also indicate a failure in more than one CIS Control.
upvoted 0 times
...
Claudia
2 months ago
I think the loghost time being out-of-sync with an external host is also a failure in multiple CIS Controls.
upvoted 0 times
...
Dortha
2 months ago
I agree, having logs from undocumented servers is a big issue.
upvoted 0 times
...
...
Jennie
3 months ago
I disagree, I believe scenario A is the one that shows a failure in multiple controls.
upvoted 0 times
...
Ellen
3 months ago
I think scenario D indicates a failure in more than one CIS Control.
upvoted 0 times
...

Save Cancel