nerdexam
CompTIA

CAS-005 · Question #78

A cybersecurity architect is reviewing the detection and monitoring capabilities for a global company that recently made multiple acquisitions. The architect discovers that the acquired companies…

The correct answer is A. Sigma rules. To create a collection of use cases for detecting known threats and include them in a centralized library for use across multiple companies with different vendors, Sigma rules are the best option. Vendor-Agnostic Format: Sigma rules are a generic and open standard for writing…

Submitted by parkjh· Mar 6, 2026Security Architecture

Question

A cybersecurity architect is reviewing the detection and monitoring capabilities for a global company that recently made multiple acquisitions. The architect discovers that the acquired companies use different vendors for detection and monitoring. The architect's goal is to:

  • Create a collection of use cases to help detect known threats
  • Include those use cases in a centralized library for use across all

of the companies Which of the following is the best way to achieve this goal?

Options

  • ASigma rules
  • BAriel Query Language
  • CUBA rules and use cases
  • DTAXII/STIX library

How the community answered

(64 responses)
  • A
    80% (51)
  • B
    11% (7)
  • C
    3% (2)
  • D
    6% (4)

Explanation

To create a collection of use cases for detecting known threats and include them in a centralized library for use across multiple companies with different vendors, Sigma rules are the best option. Vendor-Agnostic Format: Sigma rules are a generic and open standard for writing SIEM (Security Information and Event Management) rules. They can be translated to specific query languages of different SIEM systems, making them highly versatile and applicable across various platforms. Centralized Rule Management: By using Sigma rules, the cybersecurity architect can create a centralized library of detection rules that can be easily shared and implemented across different detection and monitoring systems used by the acquired companies. This ensures consistency in threat detection capabilities. Ease of Use and Flexibility: Sigma provides a structured and straightforward format for defining detection logic. It allows for the easy creation, modification, and sharing of rules, facilitating collaboration and standardization across the organization.

Community Discussion

No community discussion yet for this question.

Full CAS-005 Practice