A security analyst learns that an attack vector, which was used as a part of a recent incident, was a well-known IoT device exploit. The analyst needs to review logs to identify the time of initial exploit. Which of the following logs should the analyst review first?
Choose an answer
Tap an option to check your answer.
Correct answer: Firewall.
Why this is the answer
The firewall log is the best place to start because it records network traffic entering and leaving the network. Since the attack vector was an IoT device exploit, it likely involved network communication to or from the device. Firewall logs would show connection attempts, blocked traffic, and successful connections, which are crucial for identifying when the initial exploit occurred. Endpoint logs would be useful for activity on the compromised device itself, but the initial network-based exploit would be visible at the network perimeter first. Application logs record events within specific applications, which might not be directly relevant to the initial network exploit of an IoT device. NAC (Network Access Control) logs track device authentication and authorization to the network, but wouldn't necessarily show the exploit itself, only the device's access status.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed