200-201 Question 202
Single answerA security analyst is investigating a potential unauthorized access attempt on a company server. The analyst examines the following log entry:
'Timestamp: 2023-10-15 10:45:23 Source IP: 192.168.1.50 Destination IP: 10.0.0.8 Action: Failed Login User: admin'
Based on this log entry, what type of evidence does it represent?
- A
Direct evidence
- B
Best evidence
- C
Corroborative evidence
- D
Indirect evidence
Show answer and explanation
Correct answer: C
Explanation
The log entry serves as corroborative evidence because it provides supporting details about a failed login attempt (e.g., timestamp, source IP, destination IP, and username). It strengthens or confirms other findings during an investigation, rather than directly proving unauthorized access occurred.
- A. Incorrect.
Direct evidence is evidence that directly proves a fact without inference, such as a video recording of the event. This log entry does not meet that criterion.
- B. Incorrect.
Best evidence refers to original, unaltered evidence, such as the original digital log file. While this entry may come from the original log, the type of evidence being referred to here is not categorized as 'best evidence' based on its context.
- C. Correct.
Corroborative evidence supports or strengthens other evidence. In this scenario, the log entry provides corroborative details (e.g., failed login attempt, timestamp, and IP addresses) that could support an investigation or other findings.
- D. Incorrect.
Indirect evidence requires inference to establish a fact. While the log entry provides information about the failed login attempt, it is more supportive in nature and not primarily inferred evidence.