CAS-002 · Question #562
The Chief Information Security Officer (CISO) has just returned from attending a security conference and now wants to implement a Security Operations Center (SOC) to improve and coordinate the…
The correct answer is A. DLP, Analytics, SIEM, Forensics, NIPS, HIPS, WIPS and eGRC. A SOC integrates multiple security tools and processes to continuously monitor, detect, and respond to threats across an enterprise environment.
Question
The Chief Information Security Officer (CISO) has just returned from attending a security conference and now wants to implement a Security Operations Center (SOC) to improve and coordinate the detection of unauthorized access to the enterprise. The CISO's biggest concern is the increased number of attacks that the current infrastructure cannot detect. Which of the following is MOST likely to be used in a SOC to address the CISO's concerns?
Options
- ADLP, Analytics, SIEM, Forensics, NIPS, HIPS, WIPS and eGRC
- BForensics, White box testing, Log correlation, HIDS, and SSO
- CVulnerability assessments, NIDP, HIDS, SCAP, Analytics and SIEM
- DeGRC, WIPS, Federated ID, Network enumerator, NIPS and Port Scanners
How the community answered
(23 responses)- A70% (16)
- B4% (1)
- C17% (4)
- D9% (2)
Why each option
A SOC integrates multiple security tools and processes to continuously monitor, detect, and respond to threats across an enterprise environment.
A comprehensive SOC requires tools spanning detection (SIEM, Analytics), prevention (NIPS, HIPS, WIPS), investigation (Forensics), data protection (DLP), and governance (eGRC). SIEM is the central component that correlates events across disparate sources to detect attacks that individual controls miss - directly addressing the CISO's concern about undetected access. The combination provides layered visibility across network, host, and wireless attack vectors.
White box testing is a vulnerability assessment technique and SSO is an identity management control - neither are real-time SOC detection or monitoring capabilities.
Vulnerability assessments and SCAP focus on compliance and configuration management of known weaknesses, not on real-time detection and response to active attacks.
Network enumerators and port scanners are offensive reconnaissance tools, not SOC detection components, and Federated ID is an identity management concept unrelated to attack detection.
Concept tested: Security Operations Center component selection
Source: https://csrc.nist.gov/publications/detail/sp/800-137/final
Topics
Community Discussion
No community discussion yet for this question.