Certified Ethical Hacker (CEH v10) — Question 65

An incident investigator asks to receive a copy of the event logs from all firewalls, proxy servers, and Intrusion Detection Systems (IDS) on the network of an organization that has experienced a possible breach of security. When the investigator attempts to correlate the information in all of the logs, the sequence of many of the logged events do not match up.
What is the most likely cause?

Answer options

Correct answer: A

Explanation

The most likely cause of the mismatched event sequences is that the network devices are not all synchronized, leading to discrepancies in timestamps. If the logs are collected from devices with different time settings, it becomes difficult to accurately correlate events. The other options, while possible, do not directly explain the issue of sequence mismatching as effectively as the lack of synchronization does.