nerdexam
CompTIA

CAS-003 · Question #550

A security analyst is reviewing logs and discovers that a company-owned computer issued to an employee is generating many alerts and warnings. The analyst continues to review the log events and…

The correct answer is D. The analyst is blue team. An analyst monitoring SIEM alerts and logs to detect and report security events is performing a defensive role, which defines the blue team in a security exercise or ongoing security operations.

Enterprise Security Operations

Question

A security analyst is reviewing logs and discovers that a company-owned computer issued to an employee is generating many alerts and warnings. The analyst continues to review the log events and discovers that a non-company-owned device from a different, unknown IP address is generating the same events. The analyst informs the manager of these findings, and the manager explains that these activities are already known and part of an ongoing events. Given this scenario, which of the following roles are the analyst, the employee, and the manager filling?

Options

  • AThe analyst is red team
  • BThe analyst is white team
  • CThe analyst is red team
  • DThe analyst is blue team

How the community answered

(57 responses)
  • A
    11% (6)
  • B
    19% (11)
  • C
    5% (3)
  • D
    65% (37)

Why each option

An analyst monitoring SIEM alerts and logs to detect and report security events is performing a defensive role, which defines the blue team in a security exercise or ongoing security operations.

AThe analyst is red team

The red team performs offensive simulated attacks against systems; log review and alert monitoring are defensive activities incompatible with a red team role.

BThe analyst is white team

The white team administers and referees security exercises, setting rules and judging outcomes, rather than performing active SIEM monitoring and reporting.

CThe analyst is red team

This choice duplicates option A; the red team conducts offensive operations and does not perform defensive log analysis.

DThe analyst is blue teamCorrect

The blue team is responsible for defensive security operations including real-time monitoring, detection of anomalous activity, and escalating findings to management. An analyst reviewing SIEM logs, identifying unusual events across multiple devices, and reporting to a manager is performing the core functions of blue team operations. The manager's awareness of the activity as an ongoing event is consistent with an authorized security exercise in which the analyst's defensive monitoring role is the blue team.

Concept tested: Security team roles - blue team defensive monitoring

Source: https://csrc.nist.gov/glossary/term/blue_team

Topics

#red team#blue team#white team#security exercise roles

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice