CSSLP · Question #396
Which of the following CANNOT be impacted directly by security monitoring?
The correct answer is D. Cryptography policy update. Security monitoring directly supports detecting intrusions and policy violations, and aids forensic analysis, but it does not directly impact the administrative process of updating a cryptography policy.
Question
Which of the following CANNOT be impacted directly by security monitoring?
Options
- AForensics analysis
- BDetecting violations of security policies and standards
- CDetecting intrusion attempts early on
- DCryptography policy update
How the community answered
(39 responses)- A8% (3)
- C3% (1)
- D90% (35)
Why each option
Security monitoring directly supports detecting intrusions and policy violations, and aids forensic analysis, but it does not directly impact the administrative process of updating a cryptography policy.
Security monitoring provides logs and event data essential for forensic analysis to understand the scope and impact of an incident.
Security monitoring systems are designed to detect activities that violate established security policies and standards, such as unauthorized access attempts or suspicious network traffic.
Continuous security monitoring, often through tools like Intrusion Detection Systems (IDS), helps in identifying and alerting about intrusion attempts in real time or very early stages, enabling a quicker response.
Cryptography policy updates are part of security policy management and governance, which is a high-level administrative decision-making process. While monitoring might reveal a need for a policy update (e.g., outdated algorithms being used), the monitoring itself does not directly perform or impact the act of updating the policy; it's a human-driven, administrative task.
Concept tested: Scope of security monitoring functions
Source: https://learn.microsoft.com/en-us/azure/sentinel/operations-guidelines
Topics
Community Discussion
No community discussion yet for this question.