CAS-001 · Question #64
Which of the following implementations of a continuous monitoring risk mitigation strategy is correct?
The correct answer is C. Audit successful and failed events, transfer logs to a centralized server, institute computer assisted. A correct continuous monitoring strategy audits both successful and failed events, transfers logs to a centralized server continuously, and uses computer-assisted audit reduction rather than manual methods or infrequent log transfers.
Question
Which of the following implementations of a continuous monitoring risk mitigation strategy is correct?
Options
- AAudit successful and failed events, transfer logs to a centralized server, institute computer assisted
- BAudit successful and critical failed events, transfer logs to a centralized server once a month, tailor
- CAudit successful and failed events, transfer logs to a centralized server, institute computer assisted
- DAudit failed events only, transfer logs to a centralized server, implement manual audit reduction, tailor
How the community answered
(32 responses)- A3% (1)
- B6% (2)
- C78% (25)
- D13% (4)
Why each option
A correct continuous monitoring strategy audits both successful and failed events, transfers logs to a centralized server continuously, and uses computer-assisted audit reduction rather than manual methods or infrequent log transfers.
Option A diverges from the correct implementation in a specific configuration detail visible in the full text of the choice, making it a subtly incomplete or incorrect continuous monitoring implementation.
Transferring logs only once a month directly violates the 'continuous' requirement and creates unacceptable detection gaps, making near-real-time incident response impossible.
Continuous monitoring per NIST SP 800-137 requires capturing both successful and failed events to detect insider threats and authorized-but-malicious activity, not just failures. Logs must flow to a centralized server on an ongoing basis to support timely detection, and computer-assisted audit reduction is necessary to process log volume at scale without human bottlenecks. This combination satisfies the core requirements of a continuous monitoring program.
Auditing only failed events misses successful but unauthorized actions such as privilege misuse or insider data exfiltration, and manual audit reduction cannot scale to meet continuous monitoring requirements.
Concept tested: Continuous monitoring log auditing strategy and centralization
Source: https://csrc.nist.gov/publications/detail/sp/800-137/final
Topics
Community Discussion
No community discussion yet for this question.