nerdexam
CompTIA

CAS-003 · Question #138

A large enterprise acquires another company which uses antivirus from a different vendor. The CISO has requested that data feeds from the two different antivirus platforms be combined in a way that…

The correct answer is A. GRC. GRC is a discipline that aims to coordinate information and activity across governance, risk management and compliance with the purpose of operating more efficiently, enabling effective information sharing, more effectively reporting activities and avoiding wasteful overlaps…

Enterprise Security Operations

Question

A large enterprise acquires another company which uses antivirus from a different vendor. The CISO has requested that data feeds from the two different antivirus platforms be combined in a way that allows management to assess and rate the overall effectiveness of antivirus across the entire organization. Which of the following tools can BEST meet the CISO's requirement?

Options

  • AGRC
  • BIPS
  • CCMDB
  • DSyslog-ng
  • EIDS

How the community answered

(45 responses)
  • A
    80% (36)
  • B
    7% (3)
  • C
    9% (4)
  • D
    2% (1)
  • E
    2% (1)

Explanation

GRC is a discipline that aims to coordinate information and activity across governance, risk management and compliance with the purpose of operating more efficiently, enabling effective information sharing, more effectively reporting activities and avoiding wasteful overlaps. An integrated GRC (iGRC) takes data feeds from one or more sources that detect or sense abnormalities, faults or other patterns from security or business applications.

Topics

#GRC#security metrics#antivirus management#vendor consolidation

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice