nerdexam
CompTIA

CAS-002 · Question #586

Continuous monitoring is a popular risk reduction technique in many large organizations with formal certification processes for IT projects. In order to implement continuous monitoring in an…

The correct answer is C. Logging must be set appropriately and alerts delivered to security staff in a timely manner. Continuous monitoring requires properly configured logging and timely delivery of alerts to security personnel who can act on them.

Enterprise Security

Question

Continuous monitoring is a popular risk reduction technique in many large organizations with formal certification processes for IT projects. In order to implement continuous monitoring in an effective manner which of the following is correct?

Options

  • AOnly security related alerts should be forwarded to the network team for resolution.
  • BAll logs must be centrally managed and access to the logs restricted only to data storage
  • CLogging must be set appropriately and alerts delivered to security staff in a timely manner.
  • DCritical logs must be monitored hourly and adequate staff must be assigned to the network

How the community answered

(34 responses)
  • A
    6% (2)
  • B
    15% (5)
  • C
    74% (25)
  • D
    6% (2)

Why each option

Continuous monitoring requires properly configured logging and timely delivery of alerts to security personnel who can act on them.

AOnly security related alerts should be forwarded to the network team for resolution.

Routing only security alerts to the network team is too narrow - security staff across multiple functions need relevant alerts, and the network team alone cannot address all security incidents.

BAll logs must be centrally managed and access to the logs restricted only to data storage

Restricting log access solely to data storage personnel defeats the purpose of monitoring, as security analysts must be able to review and act on log data.

CLogging must be set appropriately and alerts delivered to security staff in a timely manner.Correct

Effective continuous monitoring depends on two foundational elements: logging configured at the appropriate verbosity and scope to capture relevant events, and alerts being routed to security staff quickly enough to enable a timely response. Without both elements, monitoring becomes either noise-heavy or too slow to reduce risk meaningfully.

DCritical logs must be monitored hourly and adequate staff must be assigned to the network

Mandating hourly review cycles for critical logs is an arbitrary and potentially insufficient interval, and assigning staff specifically to the network overlooks the broader scope of continuous monitoring.

Concept tested: Continuous monitoring logging and alerting requirements

Source: https://csrc.nist.gov/publications/detail/sp/800-137/final

Topics

#continuous monitoring#log management#SIEM#security operations

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice