Auditing Flashcards

1
Q

Two requirements for auditing?

A

Event definition

Event detection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the three types of audit trail analysis?

A

Audit trail review after event.

Periodic review of audit trail data.

Real-time audit trail analysis (part of intrusion detection function)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are three ways to protect audit trail data?

Which is most vulnerable to intruder attack? Impractical but permanent? Most secure?

A
  1. Read/write file on host: most vulnerable
  2. Write-only device: paper trail, impractical for detailed audits but permanent.
  3. Write-once/read-many device: most secure but delayed access.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly