An employee used a company’s billing system to issue fraudulent checks. The administrator is looking for evidence of other occurrences of this activity. Which of the following should the administrator examine?
Choose an answer
Tap an option to check your answer.
Correct answer: Application logs.
Why this is the answer
Application logs are the most relevant source for investigating fraudulent checks issued through a billing system because they record user actions, transactions, and system events specific to that application. This would include details about who accessed the system, what actions they performed (e.g., creating or modifying checks), and the timestamps of these activities, directly revealing evidence of misuse. Vulnerability scanner logs record findings from security scans, not user activity within an application. IDS/IPS logs monitor network traffic for suspicious patterns or attacks, but wouldn't detail specific application-level transactions like issuing checks. Firewall logs track network connections allowed or denied, but lack the granular application data needed to identify fraudulent transactions.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed