Understanding Cisco Cybersecurity Operations Fundamentals (CBROPS) — Question 32

An employee reports that someone has logged into their system and made unapproved changes, files are out of order, and several documents have been placed in the recycle bin. The security specialist reviewed the system logs, found nothing suspicious, and was not able to determine what occurred. The software is up to date; there are no alerts from antivirus and no failed login attempts. What is causing the lack of data visibility needed to detect the attack?

Answer options

Correct answer: B

Explanation

The correct answer is B because the situation describes an unauthorized access incident likely facilitated by someone with legitimate credentials. Options A, C, and D suggest scenarios that would typically generate alerts or evidence in the logs, which contradicts the scenario's details of no suspicious activity being recorded.