Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

PECB Lead-Cybersecurity-Manager Exam - Topic 3 Question 32 Discussion

During an internal audit, a company's IT team discovered a suspicious discrepancy in network logs After analyzing the network logs, the company found that some of the logs related to user access and activities were incomplete. Certain events and actions were missing, thus, raising concerns about the company's security system. Which information security principle was violated in this case?
B) Integrity
A) Confidentiality
C) Availability

PECB Lead-Cybersecurity-Manager Exam - Topic 3 Question 32 Discussion

Actual exam question for PECB's Lead-Cybersecurity-Manager exam
Question #: 32
Topic #: 3
[All Lead-Cybersecurity-Manager Questions]

During an internal audit, a company's IT team discovered a suspicious discrepancy in network logs After analyzing the network logs, the company found that some of the logs related to user access and activities were incomplete. Certain events and actions were missing, thus, raising concerns about the company's security system. Which information security principle was violated in this case?

Show Suggested Answer Hide Answer
Suggested Answer: B

The scenario describes a situation where the company's IT team discovered a discrepancy in network logs, with some logs related to user access and activities being incomplete. This situation points to a violation of the information security principle of integrity.

Integrity in information security refers to the accuracy and completeness of data and information. It ensures that data is not altered or tampered with and remains consistent and accurate. Incomplete network logs suggest that data might have been manipulated, deleted, or not properly recorded, compromising the integrity of the logging system.

Maintaining log integrity is crucial for security monitoring, forensic analysis, and compliance with regulatory requirements. When logs are incomplete, it becomes challenging to detect unauthorized access, investigate incidents, and maintain trust in the system's accuracy.


ISO/IEC 27001:2013 - This standard includes requirements for establishing, implementing, maintaining, and continually improving an information security management system (ISMS). It emphasizes the importance of maintaining the integrity of information.

NIST SP 800-92 - Provides guidelines for computer security log management, highlighting the importance of ensuring the integrity and reliability of log data to support effective security monitoring and incident response.

Integrity violations can have serious consequences, including undetected security breaches, inability to comply with legal and regulatory requirements, and loss of trust in the organization's information systems.

Contribute your Thoughts:

0/2000 characters
I lean towards integrity too, but I wonder if there could be a case for confidentiality since missing logs might expose sensitive actions.
upvoted 0 times
...
Maybelle
5 days ago
This sounds like a violation of availability because if logs are missing, it could affect access to important information, right?
upvoted 0 times
...
Shayne
10 days ago
I'm not entirely sure, but I remember a practice question about logs and their importance for maintaining integrity.
upvoted 0 times
...
Leeann
15 days ago
I think this might relate to integrity since the logs are incomplete, which means the data isn't accurate.
upvoted 0 times
...

Save Cancel