nerdexam
CompTIA

CAS-001 · Question #320

Continuous monitoring is a popular risk reduction technique in many large organizations with formal certification processes for IT projects. In order to implement continuous monitoring in an…

The correct answer is C. Logging must be set appropriately and alerts delivered to security staff in a timely manner. Answer C is correct because it captures the two essential pillars of effective continuous monitoring: (1) logging must be configured appropriately - meaning the right events are captured at the right verbosity - and (2) alerts must reach security staff in a timely manner so…

Enterprise Security

Question

Continuous monitoring is a popular risk reduction technique in many large organizations with formal certification processes for IT projects. In order to implement continuous monitoring in an effective manner which of the following is correct?

Options

  • AOnly security related alerts should be forwarded to the network team for resolution.
  • BAll logs must be centrally managed and access to the logs restricted only to data storage staff.
  • CLogging must be set appropriately and alerts delivered to security staff in a timely manner.
  • DCritical logs must be monitored hourly and adequate staff must be assigned to the network team.

How the community answered

(53 responses)
  • A
    8% (4)
  • B
    2% (1)
  • C
    89% (47)
  • D
    2% (1)

Explanation

Answer C is correct because it captures the two essential pillars of effective continuous monitoring: (1) logging must be configured appropriately - meaning the right events are captured at the right verbosity - and (2) alerts must reach security staff in a timely manner so they can respond before damage escalates. Answer A is incorrect because continuous monitoring is not limited to security alerts; operational, compliance, and availability events also require monitoring. Answer B is incorrect because restricting log access only to storage staff would prevent security analysts and incident responders from doing their jobs - logs need to be accessible to the right security personnel. Answer D is overly prescriptive and incorrect; 'hourly' is too infrequent for many critical events and the monitoring cadence should be based on risk, not a fixed interval.

Topics

#continuous monitoring#log management#security alerting#risk reduction

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice