A continuous security monitoring analyst notices a critical server has not reported logs to the SIEM for 72 hours. What is the MOST appropriate response?
Select an answer to reveal the explanation.
Short Explanation
Here's the deal — a is correct because gaps in log collection from critical systems may indicate a compromised server where an attacker disabled logging, a misconfiguration, or a connectivity failure. All possibilities must be investigated.
Full Explanation
A is correct because gaps in log collection from critical systems may indicate a compromised server where an attacker disabled logging, a misconfiguration, or a connectivity failure. All possibilities must be investigated. The 72-hour blind spot may conceal malicious activity. B is wrong because assuming decommission without verification could mask an active compromise. C is wrong because waiting extends the potential blind spot during which damage could continue. D is wrong because restarting the agent without investigation may destroy forensic evidence of why it stopped.