nerdexam
CompTIA

CAS-001 · Question #91

The Chief Information Security Officer (CISO) has just returned from attending a security conference and now wants to implement a Security Operations Center (SOC) to improve and coordinate the…

The correct answer is A. DLP, Analytics, SIEM, Forensics, NIPS, HIPS, WIPS and eGRC. A Security Operations Center (SOC) requires a comprehensive suite of detection and response tools. Option A includes: SIEM (centralized log aggregation and correlation), NIPS/HIPS/WIPS (intrusion prevention across network, host, and wireless vectors), DLP (data loss…

Enterprise Security

Question

The Chief Information Security Officer (CISO) has just returned from attending a security conference and now wants to implement a Security Operations Center (SOC) to improve and coordinate the detection of unauthorized access to the enterprise. The CISO's biggest concern is the increased number of attacks that the current infrastructure cannot detect. Which of the following is MOST likely to be used in a SOC to address the CISO's concerns?

Options

  • ADLP, Analytics, SIEM, Forensics, NIPS, HIPS, WIPS and eGRC
  • BForensics, White box testing, Log correlation, HIDS, and SSO
  • CVulnerability assessments, NIDP, HIDS, SCAP, Analytics and SIEM
  • DeGRC, WIPS, Federated ID, Network enumerator, NIPS and Port Scanners

How the community answered

(37 responses)
  • A
    73% (27)
  • B
    16% (6)
  • C
    8% (3)
  • D
    3% (1)

Explanation

A Security Operations Center (SOC) requires a comprehensive suite of detection and response tools. Option A includes: SIEM (centralized log aggregation and correlation), NIPS/HIPS/WIPS (intrusion prevention across network, host, and wireless vectors), DLP (data loss prevention), Forensics (incident investigation), and eGRC (governance, risk, and compliance management). Together these address the CISO's concern about undetected attacks across all attack surfaces. Option B includes White box testing and SSO, which are not SOC detection tools. Option C is missing DLP and WIPS. Option D includes offensive tools like network enumerators and port scanners, which are inappropriate for a defensive SOC.

Topics

#SOC#SIEM#intrusion detection#security monitoring

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice