nerdexam
CompTIA

CAS-001 · Question #233

Due to a new regulation, a company has to increase active monitoring of security-related events to 24 hours a day. The security staff only has three full time employees that work during normal…

The correct answer is C. Establish a mutually agreed upon service level agreement. A Service Level Agreement (SLA) is the formal, mutually agreed-upon contract that defines specific, measurable performance expectations - response times, escalation procedures, uptime guarantees, reporting cadence - and the remedies if those standards are not met. It is the…

Integration of Computing, Communications and Business Disciplines

Question

Due to a new regulation, a company has to increase active monitoring of security-related events to 24 hours a day. The security staff only has three full time employees that work during normal business hours. Instead of hiring new security analysts to cover the remaining shifts necessary to meet the monitoring requirement, the Chief Information Officer (CIO) has hired a Managed Security Service (MSS) to monitor events. Which of the following should the company do to ensure that the chosen MSS meets expectations?

Options

  • ADevelop a memorandum of understanding on what the MSS is responsible to provide.
  • BCreate internal metrics to track MSS performance.
  • CEstablish a mutually agreed upon service level agreement.
  • DIssue a RFP to ensure the MSS follows guidelines.

How the community answered

(43 responses)
  • A
    7% (3)
  • B
    2% (1)
  • C
    88% (38)
  • D
    2% (1)

Explanation

A Service Level Agreement (SLA) is the formal, mutually agreed-upon contract that defines specific, measurable performance expectations - response times, escalation procedures, uptime guarantees, reporting cadence - and the remedies if those standards are not met. It is the primary legal and operational tool for holding a third-party service provider accountable. Option A (MOU) is a less formal document typically used for cooperation agreements between internal parties or government entities; it lacks the enforcement mechanisms of an SLA. Option B (internal metrics) is useful for tracking performance but does not obligate the MSS to any standard. Option D (RFP) is a procurement document used to select a vendor, not to govern ongoing performance after the contract is signed.

Topics

#SLA#managed security services#outsourcing#monitoring

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice