nerdexam
CompTIA

CAS-002 · Question #220

A retail bank has had a number of issues in regards to the integrity of sensitive information across all of its customer databases. This has resulted in the bank's share price decreasing in value by…

The correct answer is B. Implement an aggregation based SIEM solution to be deployed on the log servers of the major C. Implement a security operations center to provide real time monitoring and incident response F. Ensure appropriate auditing is enabled to capture the required information. The requirements demand enterprise coverage, real-time monitoring, minimal performance impact, and meaningful reporting. Answer F (appropriate auditing enabled) is foundational-audit logs must be generated before any SIEM can consume them. Answer B (aggregation-based SIEM)…

Technical Integration of Enterprise Components

Question

A retail bank has had a number of issues in regards to the integrity of sensitive information across all of its customer databases. This has resulted in the bank's share price decreasing in value by 50% and regulatory intervention and monitoring. The new Chief Information Security Officer (CISO) as a result has initiated a program of work to solve the issues. The business has specified that the solution needs to be enterprise grade and meet the following requirements:

  • Be across all major platforms, applications and infrastructure.
  • Be able to track user and administrator activity.
  • Does not significantly degrade the performance of production

platforms, applications, and infrastructures.

  • Real time incident reporting.
  • Manageable and has meaningful information.
  • Business units are able to generate reports in a timely manner of the

unit's system assets. In order to solve this problem, which of the following security solutions will BEST meet the above requirements? (Select THREE).

Options

  • AImplement a security operations center to provide real time monitoring and incident response
  • BImplement an aggregation based SIEM solution to be deployed on the log servers of the major
  • CImplement a security operations center to provide real time monitoring and incident response
  • DEnsure that the network operations center has the tools to provide real time monitoring and
  • EImplement an agent only based SIEM solution to be deployed on all major platforms,
  • FEnsure appropriate auditing is enabled to capture the required information.
  • GManually pull the logs from the major platforms, applications, and infrastructures to a central

How the community answered

(44 responses)
  • A
    18% (8)
  • B
    66% (29)
  • D
    2% (1)
  • E
    5% (2)
  • G
    9% (4)

Explanation

The requirements demand enterprise coverage, real-time monitoring, minimal performance impact, and meaningful reporting. Answer F (appropriate auditing enabled) is foundational-audit logs must be generated before any SIEM can consume them. Answer B (aggregation-based SIEM) collects logs centrally without requiring heavy agents on every system, meeting the 'does not significantly degrade performance' requirement while enabling correlation and real-time alerting across platforms. Answer C (Security Operations Center) provides the human analysis, real-time incident response, and meaningful reporting that the business requires. Option A mentions SOC without the SIEM infrastructure, missing the technical collection layer. Option E (agent-only SIEM on ALL systems) risks performance degradation, violating a stated requirement. Option G (manual log pulls) cannot meet the real-time requirement. Option D (NOC) lacks the security-specific tooling and expertise.

Topics

#SIEM#log aggregation#security operations center#audit logging

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice