CCSP Domain 5: Logging Flashcards
1
Q
What do cloud providers commonly make available to retrieve forensic data from a cloud provider’s native logging facility?
A
APIs; carefully document the process, queries, and other details to ensure her data is forensically sound
2
Q
What information is most critical to log to ensure it is possible to properly identify ephemeral systems?
A
tags
3
Q
What is SIEM normalization?
A
SIEM normalizes incoming data to ensure that the data from variety of sources is presented consistently