nerdexam
CompTIA

CAS-002 · Question #754

A large enterprise acquires another company which uses antivirus from a different vendor. The CISO has requested that data feeds from the two different antivirus platforms be combined in a way that…

The correct answer is A. GRC. A GRC (Governance, Risk, and Compliance) platform is designed to aggregate security data from heterogeneous tools, normalize it, and present unified management reporting on overall security effectiveness.

Integration of Computing, Communications and Business Disciplines

Question

A large enterprise acquires another company which uses antivirus from a different vendor. The CISO has requested that data feeds from the two different antivirus platforms be combined in a way that allows management to assess and rate the overall effectiveness of antivirus across the entire organization. Which of the following tools can BEST meet the CISO's requirement?

Options

  • AGRC
  • BIPS
  • CCMDB
  • DSyslog-ng
  • EIDS

How the community answered

(33 responses)
  • A
    79% (26)
  • B
    6% (2)
  • C
    3% (1)
  • D
    3% (1)
  • E
    9% (3)

Why each option

A GRC (Governance, Risk, and Compliance) platform is designed to aggregate security data from heterogeneous tools, normalize it, and present unified management reporting on overall security effectiveness.

AGRCCorrect

GRC platforms are purpose-built to ingest data feeds from disparate security tools across an enterprise, including multiple antivirus vendors, and consolidate that information into dashboards and reports that allow management to assess and rate overall security effectiveness. This directly satisfies the CISO's requirement to evaluate antivirus performance across the combined organization from a single management view.

BIPS

An IPS (Intrusion Prevention System) actively blocks network-based threats in real time and does not aggregate or report on antivirus effectiveness across platforms.

CCMDB

A CMDB (Configuration Management Database) tracks IT asset inventory and configuration state but is not designed to consume or correlate antivirus telemetry for effectiveness reporting.

DSyslog-ng

Syslog-ng is a log forwarding and aggregation daemon that can collect log data but lacks the governance dashboards, risk scoring, and management reporting capabilities required to rate antivirus effectiveness.

EIDS

An IDS (Intrusion Detection System) monitors network traffic for known attack signatures and does not consolidate or evaluate endpoint antivirus data from multiple vendors.

Concept tested: GRC platform for multi-vendor security data aggregation

Source: https://csrc.nist.gov/publications/detail/sp/800-137/final

Topics

#GRC#antivirus management#security metrics#enterprise visibility

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice