300-220 · Question #39
A recommended change to enhance detection methodology includes: (Choose two)
The correct answer is B. Regularly updating and testing the incident response plan C. Enhancing data collection and normalization processes. Regularly updating and testing the incident response plan (B) ensures your team can actually execute when a threat is detected - a plan that's never tested is a plan that fails under pressure. Enhancing data collection and normalization processes (C) directly strengthens…
Question
A recommended change to enhance detection methodology includes: (Choose two)
Options
- ASimplifying the cybersecurity toolset to a single solution
- BRegularly updating and testing the incident response plan
- CEnhancing data collection and normalization processes
- DIgnoring the need for employee cybersecurity awareness training
How the community answered
(22 responses)- A5% (1)
- B91% (20)
- D5% (1)
Explanation
Regularly updating and testing the incident response plan (B) ensures your team can actually execute when a threat is detected - a plan that's never tested is a plan that fails under pressure. Enhancing data collection and normalization processes (C) directly strengthens detection by ensuring logs and telemetry from diverse sources are complete, consistent, and actionable for analysis tools like SIEMs.
Why the distractors are wrong:
- A is counterproductive - consolidating to a single tool creates blind spots; defense-in-depth relies on layered, diverse tooling.
- D is the opposite of best practice - human error drives most breaches, making employee awareness training one of the highest-ROI security investments.
Memory tip: Think "Test and Collect" - you need to test your response readiness (B) and collect quality data to detect threats (C). Both are proactive improvements; A and D both reduce capability, which is always a red flag in detection methodology questions.
Topics
Community Discussion
No community discussion yet for this question.