712-50 · Question #331
You currently cannot provide for 24/7 coverage of your security monitoring and incident response duties and your company is resistant to the idea of adding more full-time employees to the payroll…
The correct answer is B. Contract with a managed security provider and have current staff on recall for incident response. Option B is correct because a Managed Security Service Provider (MSSP) delivers round-the-clock monitoring without adding headcount, while keeping current staff available on-call for incident response decisions that require internal context - directly solving both the coverage…
Question
You currently cannot provide for 24/7 coverage of your security monitoring and incident response duties and your company is resistant to the idea of adding more full-time employees to the payroll. Which combination of solutions would help to provide the coverage needed without the addition of more dedicated staff? (choose the best answer):
Options
- ADeploy a SEIM solution and have current staff review incidents first thing in the morning
- BContract with a managed security provider and have current staff on recall for incident response
- CConfigure your syslog to send SMS messages to current staff when target events are triggered
- DEmploy an assumption of breach protocol and defend only essential information resources
How the community answered
(19 responses)- B84% (16)
- C5% (1)
- D11% (2)
Explanation
Option B is correct because a Managed Security Service Provider (MSSP) delivers round-the-clock monitoring without adding headcount, while keeping current staff available on-call for incident response decisions that require internal context - directly solving both the coverage gap and the hiring constraint.
Why the distractors fail:
- A is wrong because reviewing a SIEM only in the morning creates a massive detection gap overnight - breaches don't wait for business hours.
- C is wrong because SMS alerts still require staff to be actively available 24/7 to respond; it doesn't solve coverage, it just improves alerting for the same understaffed team.
- D is wrong because "assume breach" is a defensive posture/philosophy, not a coverage solution - it doesn't provide monitoring or incident response capability at all.
Memory tip: Think of an MSSP as a security co-pilot - they fly the plane overnight while your crew is on standby. The key phrase on the exam is "without dedicated staff" paired with "24/7 coverage," which almost always points to outsourcing monitoring (MSSP) rather than technology alone (SIEM, SMS) or a strategy shift (assume breach).
Topics
Community Discussion
No community discussion yet for this question.