Study. uk . com
  1. Home
  2. All questions
  3. Question 233

CompTIA Security+ study material · question 233 of 611

A monitoring team asks for an alert on repeated failed logins in an internal application, but the application emits no such event. What does this illustrate?

  1. That the SIEM needs additional parsers
  2. That failed logins should be blocked rather than logged
  3. That logging must be designed into the application, not added afterwards
  4. That the log retention period is too short
Show the answer

Answer: C. That logging must be designed into the application, not added afterwards

No amount of downstream tooling can recover an event the application never produced.

Source: OWASP Logging Cheat Sheet (OWASP) — OWASP Logging Cheat Sheet › Which events to log

Challenge yourself on this topic → Study as cards