CAS-002 · Question #45
Which of the following implementations of a continuous monitoring risk mitigation strategy is correct?
The correct answer is C. Audit successful and failed events, transfer logs to a centralized server, institute computer. A correct continuous monitoring strategy requires: auditing both successful AND failed events (failed-only misses successful attacks; success-only misses intrusion attempts), centralizing logs to a SIEM or log server for correlation and analysis, and implementing automated…
Question
Which of the following implementations of a continuous monitoring risk mitigation strategy is correct?
Options
- AAudit successful and failed events, transfer logs to a centralized server, institute computer
- BAudit successful and critical failed events, transfer logs to a centralized server once a month,
- CAudit successful and failed events, transfer logs to a centralized server, institute computer
- DAudit failed events only, transfer logs to a centralized server, implement manual audit
How the community answered
(49 responses)- A2% (1)
- C94% (46)
- D4% (2)
Explanation
A correct continuous monitoring strategy requires: auditing both successful AND failed events (failed-only misses successful attacks; success-only misses intrusion attempts), centralizing logs to a SIEM or log server for correlation and analysis, and implementing automated alerting and review processes rather than manual ones. Option C represents this correctly by including automated computer-based alerting and continuous review. Option A also audits both event types and uses centralized logging but likely describes a less automated or less continuous review cycle. Option B transfers logs only monthly - this is not continuous monitoring. Option D audits only failed events (misses successful attacks) and relies on manual auditing, which is neither continuous nor scalable.
Topics
Community Discussion
No community discussion yet for this question.