300-220 · Question #14
Effective tools and configurations for detection should:
The correct answer is B. Be regularly updated and patched. Effective detection tools and configurations must be regularly updated and patched (B) because threats, attack signatures, and vulnerabilities evolve constantly - an outdated detection tool may miss newly discovered attack vectors entirely, rendering it useless against modern…
Question
Effective tools and configurations for detection should:
Options
- AOnly include open-source solutions
- BBe regularly updated and patched
- CBe chosen based on the security team's familiarity
- DAlways be the most expensive option for effectiveness
How the community answered
(29 responses)- A3% (1)
- B93% (27)
- D3% (1)
Explanation
Effective detection tools and configurations must be regularly updated and patched (B) because threats, attack signatures, and vulnerabilities evolve constantly - an outdated detection tool may miss newly discovered attack vectors entirely, rendering it useless against modern threats.
Why the distractors fail:
- A is wrong because tool selection should be based on capability and fit, not licensing model - many commercial tools outperform open-source alternatives in specific contexts.
- C is a partial truth that becomes a trap: familiarity matters for operation, but it should never override a tool's effectiveness or suitability for the environment.
- D is wrong because cost does not equal effectiveness - many budget-friendly or free tools (e.g., Snort, Suricata) are industry-standard, while expensive tools may be overkill or poorly suited to a given architecture.
Memory tip: Think of detection tools like antivirus software - even the best tool on day one becomes a liability if never updated. "Stale signatures = blind spots."
Topics
Community Discussion
No community discussion yet for this question.