nerdexam
CompTIA

CAS-003 · Question #594

An organization is struggling to differentiate threats from normal traffic and access to systems. A security engineer has been asked to recommend a system that will aggregate data and provide…

The correct answer is B. SIEM. A SIEM aggregates and correlates log data from across the environment to provide centralized visibility and actionable metrics for detecting threats and anomalous activity.

Enterprise Security Operations

Question

An organization is struggling to differentiate threats from normal traffic and access to systems. A security engineer has been asked to recommend a system that will aggregate data and provide metrics that will assist in identifying malicious actors or other anomalous activity throughout the environment. Which of the following solutions should the engineer recommend?

Options

  • AWeb application firewall
  • BSIEM
  • CIPS
  • DUTM
  • EFile integrity monitor

How the community answered

(44 responses)
  • B
    91% (40)
  • C
    2% (1)
  • D
    5% (2)
  • E
    2% (1)

Why each option

A SIEM aggregates and correlates log data from across the environment to provide centralized visibility and actionable metrics for detecting threats and anomalous activity.

AWeb application firewall

A web application firewall inspects and filters HTTP/S traffic destined for web applications but does not aggregate multi-source data or provide environment-wide threat visibility.

BSIEMCorrect

A Security Information and Event Management system ingests, normalizes, and correlates log and event data from endpoints, servers, network devices, and applications into a single platform. It provides dashboards, alerts, and behavioral analytics that allow security engineers to establish baselines and identify deviations indicative of malicious actors or compromised systems. This directly satisfies the requirement for a solution that aggregates data and produces metrics to differentiate threats from normal traffic.

CIPS

An IPS monitors and blocks malicious network traffic in real time but is scoped to network-layer detection and does not aggregate logs or provide the broad analytics described.

DUTM

A UTM device consolidates multiple perimeter security functions but operates at the network edge and does not aggregate data from internal systems or provide enterprise-wide behavioral metrics.

EFile integrity monitor

A file integrity monitor detects unauthorized changes to specific files and directories but has a narrow scope and cannot correlate data across multiple systems to identify broader threat patterns.

Concept tested: SIEM for centralized log aggregation and threat detection

Source: https://csrc.nist.gov/glossary/term/security_information_and_event_management

Topics

#SIEM#log aggregation#anomaly detection#threat detection

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice