A continuous security monitoring analyst notices a critical server has not reported logs to the SIEM for 72 hours. What is the MOST appropriate response?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — a is correct because gaps in log collection from critical systems may indicate a compromised server where an attacker disabled logging, a misconfiguration, or a connectivity failure. All possibilities must be investigated.
Full explanation below image
Full Explanation
A is correct because gaps in log collection from critical systems may indicate a compromised server where an attacker disabled logging, a misconfiguration, or a connectivity failure. All possibilities must be investigated. The 72-hour blind spot may conceal malicious activity. B is wrong because assuming decommission without verification could mask an active compromise. C is wrong because waiting extends the potential blind spot during which damage could continue. D is wrong because restarting the agent without investigation may destroy forensic evidence of why it stopped.