Question: You are an engineer on the IT Security Operations team and are contacted by a server administrator. While troubleshooting performance problems on an Internet -
You are an engineer on the IT Security Operations team and are contacted by a server administrator. While troubleshooting performance problems on an Internetaccessible web server, she discovered a process that she didnt recognize, that seemed to be taking up a lot of CPU time. You do some quick internet searches for the process name, but cannot find any results.
The server administrator tells you that the web server hosts the public website for your organization; it provides public information about the organization, including contact information, public meeting agendas and minutes, program missions and achievements, and services available. The server is running a web service and application middleware; most of the web site content is stored on a separate database server.
In which of the following locations would you LEAST expect to find information about how the server was compromised?
System event logs eg syslog on a Unix server, or Windows event logs on a Windows server
Database transaction logs
Filesystem metadata
Web server logs
Step by Step Solution
There are 3 Steps involved in it
1 Expert Approved Answer
Step: 1 Unlock
Question Has Been Solved by an Expert!
Get step-by-step solutions from verified subject matter experts
Step: 2 Unlock
Step: 3 Unlock
