After a suspected intrusion on a critical permits server, investigators find large gaps where security and authentication logs should exist. What malicious indicator does this most strongly suggest?
Select an answer to reveal the explanation.
Short Explanation
Missing logs after a break-in are the wiped security camera tape. Attackers love deleting or turning off logging so you cannot reconstruct the crime—treat the gap itself as a clue.
Full Explanation
Absent, truncated, or out-of-cycle logging on a critical system after intrusion is a classic indicator of anti-forensic behavior intended to cover tracks. Disk-full noise limited to temp files, allow listing success, and intentional isolation are not explanations for security-log gaps following compromise.