An offline audit log contains the source IP address of a session suspected to have exploited a vulnerability resulting in system compromise. Which kind of evidence is this IP address?
"B is correct.
There are 3 types of evidences:
Best: Do not need anything else.
Corroborating: evidence that tends to support a theory or an assumption deduced by some initial evidence.
Indirect: extrapolation to a conclusion of fact (such as fingerprints, DNA evidence, and so on)
In this case the IP address would corroborate to some other evidence.
Corroborative evidence supports some other evidence, yet the question does not state that their is any other evidence than this log entry and a suspicion. Seems more like this would be circumstantial evidence at the very most and may not even be 'evidence' at all - its just a log entry.
Three types of Evidence:
Best Evidence
- Original, unaltered evidence. In court, this is preferred over secondary evidence.
- The best evidence rule is a legal principle that holds an original copy of a document as superior evidence.
Corroborative Evidence
- It is an evidence that strengthens or confirms already existing evidence.
Indirect Evidence (Circumstantial Evidence)
- It is an evidence that relies on an inference to connect it to a conclusion of fact. Like a fingerprint, DNA etc. at the scene of a crime.
https://vwannabe.com/2018/01/02/ccna-cyber-ops-secops-1-0/#:~:text=Corroborative%20evidence%3A%20(or%20corroboration),therefore%20confirming%20the%20original%20proposition.
i think B. is correct answer.
Corroborating evidence ==> is evidence that strengthens or confirms already existing evidence.
** in this case ==> ip address would corroborate the current evidence.
upvoted 3 times
...
This section is not available anymore. Please use the main Exam Page.200-201 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
anonymous1966
Highly Voted 2 years, 3 months agoqz999
Highly Voted 2 years, 3 months agoSecurityGuy
Most Recent 9 months agoEng_ahmedyoussef
1 year, 2 months ago