Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam CISSP topic 1 question 165 discussion

Actual exam question from ISC's CISSP
Question #: 165
Topic #: 1
[All CISSP Questions]

A developer is creating an application that requires secure logging of all user activity. What is the BEST permission the developer should assign to the log file to ensure requirements are met?

  • A. Execute
  • B. Read
  • C. Write
  • D. Append
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Rollizo
Highly Voted 1 year, 7 months ago
I think that it is D: Append Data allows or denies making changes to the end of the file but not changing, deleting, or overwriting existing data (applies to files only). You are no interested in the application delete previous logs.
upvoted 10 times
jackdryan
1 year ago
D is correct
upvoted 1 times
...
...
klarak
Most Recent 3 weeks, 2 days ago
Selected Answer: D
I'm not sure if this question is accurate but I think what they're getting at is D because best practice is to set your log files to Append rather than overwrite previous entries in their log files. The first 3 are irrelevant.
upvoted 1 times
klarak
2 weeks, 5 days ago
Other commenters have me convinced this should be write
upvoted 1 times
...
...
homeysl
1 month, 3 weeks ago
Selected Answer: C
It needs to write file
upvoted 1 times
...
GuardianAngel
3 months ago
The following are the common types of rights that can be assigned to log files: Read: This permission allows users or processes to view the contents of the log file. Reading from log files is essential for monitoring system activity, troubleshooting issues, and analyzing historical data. Write: This permission allows users or processes to modify or append to the contents of the log file. Writing to log files is necessary for recording new events, updating log entries, or adding additional information. Execute: In some cases, log files may have execute permissions, allowing them to be executed as scripts or programs. However, this is less common for log files and is typically reserved for executable files.
upvoted 1 times
...
GPrep
4 months, 1 week ago
Selected Answer: C
C - I've found no evidence that "append" is actually a file system permissions option. Write would be the right option here. The ability to delete/modify data is included in that, however, if Append isn't a valid option, write is the only option left. If anyone has direct evidence of append being a permission option, I'd like to learn, please share it. Windows has the "create folder / append data" option, though my testing doesn't show it does what I would assume it can do.
upvoted 4 times
...
Soleandheel
5 months ago
D. Append To ensure secure logging of all user activity, the developer should assign the "Append" permission to the log file. This permission allows new log entries to be added to the existing log file without overwriting or deleting the previous entries, ensuring that a complete record of user activity is maintained. It prevents users from modifying or deleting log entries, which is essential for maintaining the integrity of the log file for security and auditing purposes.
upvoted 1 times
...
74gjd_37
7 months, 3 weeks ago
Selected Answer: D
There is the append permission in Windows and in many cloud storage types, see https://en.wikipedia.org/wiki/Append-only
upvoted 1 times
...
Yokota
10 months, 1 week ago
Selected Answer: C
This permission allows writing or modifying the contents of the file, making it essential for the application to log user activity securely.
upvoted 1 times
...
HughJassole
11 months, 2 weeks ago
I am a Linux admin and there is no "append" in Linux. The developer doesn't assign permissions; sysadmins do. The app would need write permission but for everyone else it should be probably no access or just read.
upvoted 4 times
...
Alex71
1 year, 2 months ago
Selected Answer: D
The BEST permission the developer should assign to the log file to ensure secure logging of all user activity is the "Append" permission. The "Append" permission allows new data to be added to the end of a file without overwriting or modifying any existing data in the file. This is important for secure logging of user activity because it ensures that the log file cannot be tampered with or modified by anyone, including the application itself. If the log file had the "Write" permission, then it would be possible for someone or something to modify or overwrite existing log data, which could compromise the integrity and security of the log file. The "Read" permission is not relevant for this use case since it only allows someone to view the contents of the file. The "Execute" permission is also not relevant since it only applies to executable files, which the log file is not. Therefore, the "Append" permission is the BEST permission to ensure secure logging of all user activity.
upvoted 3 times
...
Bhuraw
1 year, 6 months ago
Selected Answer: D
Append is stricter than write
upvoted 2 times
...
[Removed]
1 year, 6 months ago
Approaching this from the perspective of least privilege, D > C in this regard.
upvoted 2 times
...
ataaf
1 year, 7 months ago
the answer is correct. log files should be write only so the application can write to it.
upvoted 4 times
Loveguitar
1 year, 7 months ago
I get it now, the focus is on the application's permission not the users of the application. Thanks
upvoted 2 times
dmo_d
1 year ago
Why? Append permissions apply to applications, too.
upvoted 1 times
...
...
...
Loveguitar
1 year, 7 months ago
Shouldn't it be read access, like in WORM (write once and read many) so no one can modify the logs?
upvoted 2 times
Nickolos
1 year, 5 months ago
Read access in computing is a permission to access files or directories where the user (or application in this case) is only allowed to read or view, not to make changes. So no, read access would be incorrect for this question.
upvoted 1 times
...
...
projtfer
1 year, 7 months ago
Selected Answer: D
I concur with Rollizo, write permission would enable someone to modify, append is the best answer!
upvoted 1 times
franbarpro
1 year, 6 months ago
Appending data to a file requires write permission on the file itself.
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...