ISC2 CISSP Logging SIEM Threat Intelligence And UEBA Practice Test
7 Security Operations • 20 original questions
This CISSP practice test focuses on logging siem threat intelligence and ueba through original scenario-based questions aligned to the current ISC2 CISSP Certification Exam Outline. Use the full ExamSnap CISSP collection for practice across all eight domains. For broader exam preparation, review the ISC2 CISSP Exam Dumps page.
Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.
During a risk workshop for the remote access service, the team identifies User and Entity Behavior Analytics (UEBA) as the deciding issue. The security architect is expected to address the control objective without replacing governance with a technology-only shortcut. What is the MOST appropriate course of action? The operating team supports 33 critical systems under documented recovery and escalation procedures.
Correct answer: D
Why: Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained. It directly addresses User and Entity Behavior Analytics (UEBA) without replacing governance with a technology-only shortcut.
Option review:
A: Personnel safety takes precedence over property and system restoration during emergencies. That action can be useful in a different security decision, but it does not most directly address User and Entity Behavior Analytics (UEBA) in this scenario.
B: Baselines and drift control make systems predictable, auditable, and recoverable. That action can be useful in a different security decision, but it does not most directly address User and Entity Behavior Analytics (UEBA) in this scenario.
C: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address User and Entity Behavior Analytics (UEBA) in this scenario.
D: Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained. It directly addresses User and Entity Behavior Analytics (UEBA) without replacing governance with a technology-only shortcut.
Learning point: Centralize protected, time-synchronized telemetry, tune detection logic, correlate events in SIEM/IDPS, and enrich monitoring with threat intelligence and behavioral analytics. Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained.
A control owner at Woodgrove Bank proposes a quick technical fix for Intrusion detection and prevention (IDPS) in the customer identity platform. The security operations manager must address the control objective while keeping the process defensible to auditors and business owners. What should happen FIRST? The operating team supports 50 critical systems under documented recovery and escalation procedures.
Correct answer: C
Why: Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained. It directly addresses Intrusion detection and prevention (IDPS) while keeping the process defensible to auditors and business owners.
Option review:
A: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Intrusion detection and prevention (IDPS) in this scenario.
B: Business continuity validates the organization’s ability to continue critical functions, not just restore technology. That action can be useful in a different security decision, but it does not most directly address Intrusion detection and prevention (IDPS) in this scenario.
C: Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained. It directly addresses Intrusion detection and prevention (IDPS) while keeping the process defensible to auditors and business owners.
D: A recovery plan only works when responsibilities, communications, restoration sequencing, and practice are explicit. That action can be useful in a different security decision, but it does not most directly address Intrusion detection and prevention (IDPS) in this scenario.
Learning point: Centralize protected, time-synchronized telemetry, tune detection logic, correlate events in SIEM/IDPS, and enrich monitoring with threat intelligence and behavioral analytics. Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained.
Relecloud Systems is standardizing security across several business units. The data analytics lake raises a question about Security Information and Event Management (SIEM). The business continuity lead needs to address the control objective while minimizing irreversible action until facts and authority are established. Which action provides the BEST governance and security outcome? The operating team supports 67 critical systems under documented recovery and escalation procedures.
Correct answer: C
Why: Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained. It directly addresses Security Information and Event Management (SIEM) while minimizing irreversible action until facts and authority are established.
Option review:
A: DR test methods trade realism against operational disruption; the test should match the assurance objective. That action can be useful in a different security decision, but it does not most directly address Security Information and Event Management (SIEM) in this scenario.
B: Risk-based vulnerability management is more effective than patching purely by severity score or release date. That action can be useful in a different security decision, but it does not most directly address Security Information and Event Management (SIEM) in this scenario.
C: Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained. It directly addresses Security Information and Event Management (SIEM) while minimizing irreversible action until facts and authority are established.
D: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Security Information and Event Management (SIEM) in this scenario.
Learning point: Centralize protected, time-synchronized telemetry, tune detection logic, correlate events in SIEM/IDPS, and enrich monitoring with threat intelligence and behavioral analytics. Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained.
During a network segmentation redesign, Contoso Financial asks the privacy and compliance lead to address Continuous monitoring and tuning for its branch-office network. The requirement is to address the control objective while preserving evidence needed for later review. What should the organization do FIRST? The operating team supports 84 critical systems under documented recovery and escalation procedures.
Correct answer: C
Why: Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained. It directly addresses Continuous monitoring and tuning while preserving evidence needed for later review.
Option review:
A: Foundational operations controls reduce concentration of privilege and make accountability visible. That action can be useful in a different security decision, but it does not most directly address Continuous monitoring and tuning in this scenario.
B: Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority. That action can be useful in a different security decision, but it does not most directly address Continuous monitoring and tuning in this scenario.
C: Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained. It directly addresses Continuous monitoring and tuning while preserving evidence needed for later review.
D: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Continuous monitoring and tuning in this scenario.
Learning point: Centralize protected, time-synchronized telemetry, tune detection logic, correlate events in SIEM/IDPS, and enrich monitoring with threat intelligence and behavioral analytics. Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained.
Lucerne Publishing is revising controls for its industrial control network. A review highlights Egress monitoring. The security architect must address the control objective without granting broader privilege than the business need requires. Which action is the BEST next step? The operating team supports 10 critical systems under documented recovery and escalation procedures.
Correct answer: B
Why: Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained. It directly addresses Egress monitoring without granting broader privilege than the business need requires.
Option review:
A: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Egress monitoring in this scenario.
B: Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained. It directly addresses Egress monitoring without granting broader privilege than the business need requires.
C: DR test methods trade realism against operational disruption; the test should match the assurance objective. That action can be useful in a different security decision, but it does not most directly address Egress monitoring in this scenario.
D: Recovery architecture should meet business objectives rather than simply maximizing technical redundancy. That action can be useful in a different security decision, but it does not most directly address Egress monitoring in this scenario.
Learning point: Centralize protected, time-synchronized telemetry, tune detection logic, correlate events in SIEM/IDPS, and enrich monitoring with threat intelligence and behavioral analytics. Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained.
An auditor asks Lamna Healthcare to demonstrate how it handles Log management in the research data repository. The security operations manager must address the control objective without creating a new single point of failure. Which response is MOST appropriate? The operating team supports 27 critical systems under documented recovery and escalation procedures.
Correct answer: B
Why: Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained. It directly addresses Log management without creating a new single point of failure.
Option review:
A: Personnel safety takes precedence over property and system restoration during emergencies. That action can be useful in a different security decision, but it does not most directly address Log management in this scenario.
B: Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained. It directly addresses Log management without creating a new single point of failure.
C: Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority. That action can be useful in a different security decision, but it does not most directly address Log management in this scenario.
D: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Log management in this scenario.
Learning point: Centralize protected, time-synchronized telemetry, tune detection logic, correlate events in SIEM/IDPS, and enrich monitoring with threat intelligence and behavioral analytics. Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained.
After a business change, Fourth Coffee discovers that Threat intelligence and threat hunting is not handled consistently for the payment processing service. The business continuity lead needs to address the control objective while ensuring that emergency access cannot become permanent access. Which recommendation BEST addresses the issue? The operating team supports 44 critical systems under documented recovery and escalation procedures.
Correct answer: D
Why: Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained. It directly addresses Threat intelligence and threat hunting while ensuring that emergency access cannot become permanent access.
Option review:
A: Incident management minimizes business impact while supporting investigation and continuous improvement. That action can be useful in a different security decision, but it does not most directly address Threat intelligence and threat hunting in this scenario.
B: Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority. That action can be useful in a different security decision, but it does not most directly address Threat intelligence and threat hunting in this scenario.
C: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Threat intelligence and threat hunting in this scenario.
D: Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained. It directly addresses Threat intelligence and threat hunting while ensuring that emergency access cannot become permanent access.
Learning point: Centralize protected, time-synchronized telemetry, tune detection logic, correlate events in SIEM/IDPS, and enrich monitoring with threat intelligence and behavioral analytics. Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained.
Consolidated Messenger is preparing a security decision for the software delivery pipeline. The decision involves User and Entity Behavior Analytics (UEBA). The privacy and compliance lead must address the control objective while allowing independent verification of the control outcome. Which option BEST reflects CISSP-level security practice? The operating team supports 61 critical systems under documented recovery and escalation procedures.
Correct answer: D
Why: Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained. It directly addresses User and Entity Behavior Analytics (UEBA) while allowing independent verification of the control outcome.
Option review:
A: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address User and Entity Behavior Analytics (UEBA) in this scenario.
B: Incident management minimizes business impact while supporting investigation and continuous improvement. That action can be useful in a different security decision, but it does not most directly address User and Entity Behavior Analytics (UEBA) in this scenario.
C: Personnel safety takes precedence over property and system restoration during emergencies. That action can be useful in a different security decision, but it does not most directly address User and Entity Behavior Analytics (UEBA) in this scenario.
D: Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained. It directly addresses User and Entity Behavior Analytics (UEBA) while allowing independent verification of the control outcome.
Learning point: Centralize protected, time-synchronized telemetry, tune detection logic, correlate events in SIEM/IDPS, and enrich monitoring with threat intelligence and behavioral analytics. Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained.
During a risk workshop for the AI-assisted customer service platform, the team identifies Intrusion detection and prevention (IDPS) as the deciding issue. The security architect is expected to address the control objective while accounting for third-party and lifecycle dependencies. What is the MOST appropriate course of action? The operating team supports 78 critical systems under documented recovery and escalation procedures.
Correct answer: D
Why: Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained. It directly addresses Intrusion detection and prevention (IDPS) while accounting for third-party and lifecycle dependencies.
Option review:
A: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Intrusion detection and prevention (IDPS) in this scenario.
B: Physical access controls should deter, detect, delay, and support response rather than rely on a single barrier. That action can be useful in a different security decision, but it does not most directly address Intrusion detection and prevention (IDPS) in this scenario.
C: Firewalls, IDS/IPS, allowlisting, sandboxing, honeypots, anti-malware, and AI tools each address different threats and require tuning. That action can be useful in a different security decision, but it does not most directly address Intrusion detection and prevention (IDPS) in this scenario.
D: Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained. It directly addresses Intrusion detection and prevention (IDPS) while accounting for third-party and lifecycle dependencies.
Learning point: Centralize protected, time-synchronized telemetry, tune detection logic, correlate events in SIEM/IDPS, and enrich monitoring with threat intelligence and behavioral analytics. Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained.
A control owner at Southridge Media proposes a quick technical fix for Security Information and Event Management (SIEM) in the global collaboration platform. The security operations manager must address the control objective while maintaining the organization’s stated risk appetite. What should happen FIRST? The operating team supports 4 critical systems under documented recovery and escalation procedures.
Correct answer: C
Why: Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained. It directly addresses Security Information and Event Management (SIEM) while maintaining the organization’s stated risk appetite.
Option review:
A: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Security Information and Event Management (SIEM) in this scenario.
B: Incident management minimizes business impact while supporting investigation and continuous improvement. That action can be useful in a different security decision, but it does not most directly address Security Information and Event Management (SIEM) in this scenario.
C: Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained. It directly addresses Security Information and Event Management (SIEM) while maintaining the organization’s stated risk appetite.
D: A recovery plan only works when responsibilities, communications, restoration sequencing, and practice are explicit. That action can be useful in a different security decision, but it does not most directly address Security Information and Event Management (SIEM) in this scenario.
Learning point: Centralize protected, time-synchronized telemetry, tune detection logic, correlate events in SIEM/IDPS, and enrich monitoring with threat intelligence and behavioral analytics. Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained.
Adventure Works is standardizing security across several business units. The e-commerce application raises a question about Continuous monitoring and tuning. The business continuity lead needs to address the control objective while meeting the business objective with the least unnecessary operational complexity. Which action provides the BEST governance and security outcome? The operating team supports 21 critical systems under documented recovery and escalation procedures.
Correct answer: A
Why: Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained. It directly addresses Continuous monitoring and tuning while meeting the business objective with the least unnecessary operational complexity.
Option review:
A: Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained. It directly addresses Continuous monitoring and tuning while meeting the business objective with the least unnecessary operational complexity.
B: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Continuous monitoring and tuning in this scenario.
C: Resource protection must follow data and media across storage, movement, reuse, and disposal. That action can be useful in a different security decision, but it does not most directly address Continuous monitoring and tuning in this scenario.
D: Physical access controls should deter, detect, delay, and support response rather than rely on a single barrier. That action can be useful in a different security decision, but it does not most directly address Continuous monitoring and tuning in this scenario.
Learning point: Centralize protected, time-synchronized telemetry, tune detection logic, correlate events in SIEM/IDPS, and enrich monitoring with threat intelligence and behavioral analytics. Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained.
During a data-governance workshop, VanArsdel Energy asks the privacy and compliance lead to address Egress monitoring for its clinical records environment. The requirement is to address the control objective while keeping the control sustainable for normal operations. What should the organization do FIRST? The operating team supports 38 critical systems under documented recovery and escalation procedures.
Correct answer: C
Why: Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained. It directly addresses Egress monitoring while keeping the control sustainable for normal operations.
Option review:
A: Firewalls, IDS/IPS, allowlisting, sandboxing, honeypots, anti-malware, and AI tools each address different threats and require tuning. That action can be useful in a different security decision, but it does not most directly address Egress monitoring in this scenario.
B: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Egress monitoring in this scenario.
C: Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained. It directly addresses Egress monitoring while keeping the control sustainable for normal operations.
D: Incident management minimizes business impact while supporting investigation and continuous improvement. That action can be useful in a different security decision, but it does not most directly address Egress monitoring in this scenario.
Learning point: Centralize protected, time-synchronized telemetry, tune detection logic, correlate events in SIEM/IDPS, and enrich monitoring with threat intelligence and behavioral analytics. Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained.
Northwind Health is revising controls for its remote access service. A review highlights Log management. The security architect must address the control objective while ensuring the decision can be repeated consistently across business units. Which action is the BEST next step? The operating team supports 55 critical systems under documented recovery and escalation procedures.
Correct answer: A
Why: Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained. It directly addresses Log management while ensuring the decision can be repeated consistently across business units.
Option review:
A: Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained. It directly addresses Log management while ensuring the decision can be repeated consistently across business units.
B: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Log management in this scenario.
C: Firewalls, IDS/IPS, allowlisting, sandboxing, honeypots, anti-malware, and AI tools each address different threats and require tuning. That action can be useful in a different security decision, but it does not most directly address Log management in this scenario.
D: DR test methods trade realism against operational disruption; the test should match the assurance objective. That action can be useful in a different security decision, but it does not most directly address Log management in this scenario.
Learning point: Centralize protected, time-synchronized telemetry, tune detection logic, correlate events in SIEM/IDPS, and enrich monitoring with threat intelligence and behavioral analytics. Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained.
An auditor asks Coho Insurance to demonstrate how it handles Threat intelligence and threat hunting in the customer identity platform. The security operations manager must address the control objective while preserving clear accountability and audit evidence. Which response is MOST appropriate? The operating team supports 72 critical systems under documented recovery and escalation procedures.
Correct answer: D
Why: Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained. It directly addresses Threat intelligence and threat hunting while preserving clear accountability and audit evidence.
Option review:
A: Baselines and drift control make systems predictable, auditable, and recoverable. That action can be useful in a different security decision, but it does not most directly address Threat intelligence and threat hunting in this scenario.
B: Resource protection must follow data and media across storage, movement, reuse, and disposal. That action can be useful in a different security decision, but it does not most directly address Threat intelligence and threat hunting in this scenario.
C: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Threat intelligence and threat hunting in this scenario.
D: Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained. It directly addresses Threat intelligence and threat hunting while preserving clear accountability and audit evidence.
Learning point: Centralize protected, time-synchronized telemetry, tune detection logic, correlate events in SIEM/IDPS, and enrich monitoring with threat intelligence and behavioral analytics. Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained.
After a business change, A. Datum Analytics discovers that Intrusion detection and prevention (IDPS) is not handled consistently for the data analytics lake. The business continuity lead needs to address the control objective while protecting sensitive data throughout the change. Which recommendation BEST addresses the issue? The operating team supports 89 critical systems under documented recovery and escalation procedures.
Correct answer: D
Why: Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained. It directly addresses Intrusion detection and prevention (IDPS) while protecting sensitive data throughout the change.
Option review:
A: Personnel safety takes precedence over property and system restoration during emergencies. That action can be useful in a different security decision, but it does not most directly address Intrusion detection and prevention (IDPS) in this scenario.
B: Resource protection must follow data and media across storage, movement, reuse, and disposal. That action can be useful in a different security decision, but it does not most directly address Intrusion detection and prevention (IDPS) in this scenario.
C: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Intrusion detection and prevention (IDPS) in this scenario.
D: Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained. It directly addresses Intrusion detection and prevention (IDPS) while protecting sensitive data throughout the change.
Learning point: Centralize protected, time-synchronized telemetry, tune detection logic, correlate events in SIEM/IDPS, and enrich monitoring with threat intelligence and behavioral analytics. Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained.
Blue Yonder Airlines is preparing a security decision for the branch-office network. The decision involves Security Information and Event Management (SIEM). The privacy and compliance lead must address the control objective while preserving availability of the critical business service. Which option BEST reflects CISSP-level security practice? The operating team supports 15 critical systems under documented recovery and escalation procedures.
Correct answer: B
Why: Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained. It directly addresses Security Information and Event Management (SIEM) while preserving availability of the critical business service.
Option review:
A: Risk-based vulnerability management is more effective than patching purely by severity score or release date. That action can be useful in a different security decision, but it does not most directly address Security Information and Event Management (SIEM) in this scenario.
B: Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained. It directly addresses Security Information and Event Management (SIEM) while preserving availability of the critical business service.
C: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Security Information and Event Management (SIEM) in this scenario.
D: Business continuity validates the organization’s ability to continue critical functions, not just restore technology. That action can be useful in a different security decision, but it does not most directly address Security Information and Event Management (SIEM) in this scenario.
Learning point: Centralize protected, time-synchronized telemetry, tune detection logic, correlate events in SIEM/IDPS, and enrich monitoring with threat intelligence and behavioral analytics. Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained.
During a risk workshop for the industrial control network, the team identifies Continuous monitoring and tuning as the deciding issue. The security architect is expected to address the control objective without replacing governance with a technology-only shortcut. What is the MOST appropriate course of action? The operating team supports 32 critical systems under documented recovery and escalation procedures.
Correct answer: C
Why: Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained. It directly addresses Continuous monitoring and tuning without replacing governance with a technology-only shortcut.
Option review:
A: Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority. That action can be useful in a different security decision, but it does not most directly address Continuous monitoring and tuning in this scenario.
B: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Continuous monitoring and tuning in this scenario.
C: Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained. It directly addresses Continuous monitoring and tuning without replacing governance with a technology-only shortcut.
D: Firewalls, IDS/IPS, allowlisting, sandboxing, honeypots, anti-malware, and AI tools each address different threats and require tuning. That action can be useful in a different security decision, but it does not most directly address Continuous monitoring and tuning in this scenario.
Learning point: Centralize protected, time-synchronized telemetry, tune detection logic, correlate events in SIEM/IDPS, and enrich monitoring with threat intelligence and behavioral analytics. Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained.
A control owner at Tailspin Logistics proposes a quick technical fix for Egress monitoring in the research data repository. The security operations manager must address the control objective while keeping the process defensible to auditors and business owners. What should happen FIRST? The operating team supports 49 critical systems under documented recovery and escalation procedures.
Correct answer: D
Why: Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained. It directly addresses Egress monitoring while keeping the process defensible to auditors and business owners.
Option review:
A: Firewalls, IDS/IPS, allowlisting, sandboxing, honeypots, anti-malware, and AI tools each address different threats and require tuning. That action can be useful in a different security decision, but it does not most directly address Egress monitoring in this scenario.
B: Incident management minimizes business impact while supporting investigation and continuous improvement. That action can be useful in a different security decision, but it does not most directly address Egress monitoring in this scenario.
C: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Egress monitoring in this scenario.
D: Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained. It directly addresses Egress monitoring while keeping the process defensible to auditors and business owners.
Learning point: Centralize protected, time-synchronized telemetry, tune detection logic, correlate events in SIEM/IDPS, and enrich monitoring with threat intelligence and behavioral analytics. Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained.
Alpine Sports is standardizing security across several business units. The payment processing service raises a question about Log management. The business continuity lead needs to address the control objective while minimizing irreversible action until facts and authority are established. Which action provides the BEST governance and security outcome? The operating team supports 66 critical systems under documented recovery and escalation procedures.
Correct answer: C
Why: Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained. It directly addresses Log management while minimizing irreversible action until facts and authority are established.
Option review:
A: Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority. That action can be useful in a different security decision, but it does not most directly address Log management in this scenario.
B: Business continuity validates the organization’s ability to continue critical functions, not just restore technology. That action can be useful in a different security decision, but it does not most directly address Log management in this scenario.
C: Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained. It directly addresses Log management while minimizing irreversible action until facts and authority are established.
D: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Log management in this scenario.
Learning point: Centralize protected, time-synchronized telemetry, tune detection logic, correlate events in SIEM/IDPS, and enrich monitoring with threat intelligence and behavioral analytics. Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained.
During a regulatory readiness assessment, Fabrikam Manufacturing asks the privacy and compliance lead to address Threat intelligence and threat hunting for its software delivery pipeline. The requirement is to address the control objective while preserving evidence needed for later review. What should the organization do FIRST? The operating team supports 83 critical systems under documented recovery and escalation procedures.
Correct answer: D
Why: Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained. It directly addresses Threat intelligence and threat hunting while preserving evidence needed for later review.
Option review:
A: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Threat intelligence and threat hunting in this scenario.
B: Recovery architecture should meet business objectives rather than simply maximizing technical redundancy. That action can be useful in a different security decision, but it does not most directly address Threat intelligence and threat hunting in this scenario.
C: Foundational operations controls reduce concentration of privilege and make accountability visible. That action can be useful in a different security decision, but it does not most directly address Threat intelligence and threat hunting in this scenario.
D: Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained. It directly addresses Threat intelligence and threat hunting while preserving evidence needed for later review.
Learning point: Centralize protected, time-synchronized telemetry, tune detection logic, correlate events in SIEM/IDPS, and enrich monitoring with threat intelligence and behavioral analytics. Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained.
Popular posts
Recent Posts
