nerdexam
CompTIA

CAS-002 · Question #45

Which of the following implementations of a continuous monitoring risk mitigation strategy is correct?

The correct answer is C. Audit successful and failed events, transfer logs to a centralized server, institute computer. A correct continuous monitoring strategy requires: auditing both successful AND failed events (failed-only misses successful attacks; success-only misses intrusion attempts), centralizing logs to a SIEM or log server for correlation and analysis, and implementing automated…

Enterprise Security

Question

Which of the following implementations of a continuous monitoring risk mitigation strategy is correct?

Options

  • AAudit successful and failed events, transfer logs to a centralized server, institute computer
  • BAudit successful and critical failed events, transfer logs to a centralized server once a month,
  • CAudit successful and failed events, transfer logs to a centralized server, institute computer
  • DAudit failed events only, transfer logs to a centralized server, implement manual audit

How the community answered

(49 responses)
  • A
    2% (1)
  • C
    94% (46)
  • D
    4% (2)

Explanation

A correct continuous monitoring strategy requires: auditing both successful AND failed events (failed-only misses successful attacks; success-only misses intrusion attempts), centralizing logs to a SIEM or log server for correlation and analysis, and implementing automated alerting and review processes rather than manual ones. Option C represents this correctly by including automated computer-based alerting and continuous review. Option A also audits both event types and uses centralized logging but likely describes a less automated or less continuous review cycle. Option B transfers logs only monthly - this is not continuous monitoring. Option D audits only failed events (misses successful attacks) and relies on manual auditing, which is neither continuous nor scalable.

Topics

#continuous monitoring#log management#security auditing#risk mitigation

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice