ExamGecko
Question list
Search
Search

Question 353 - CISM discussion

Report
Export

What type of control is being implemented when a security information and event management (SIEM) system is installed?

A.
Preventive
Answers
A.
Preventive
B.
Deterrent
Answers
B.
Deterrent
C.
Detective
Answers
C.
Detective
D.
Corrective
Answers
D.
Corrective
Suggested answer: C

Explanation:

A security information and event management (SIEM) system is a type of detective control because it monitors and analyzes the security events or logs from different sources or systems, and detects any anomalies or incidents that may indicate a security breach or compromise. A preventive control is a type of control that prevents or blocks any unauthorized or malicious activity or access from occurring. A deterrent control is a type of control that discourages or warns any potential attackers or intruders from attempting any unauthorized or malicious activity or access. A corrective control is a type of control that restores or repairs any damage or disruption caused by an unauthorized or malicious activity or access.

Reference: https://www.isaca.org/resources/isaca-journal/issues/2017/volume-6/the-value-of-penetration-testing https://www.isaca.org/resources/isaca-journal/issues/2016/volume-5/security-scanning-versus-penetration-testing

asked 01/10/2024
Ashad Conley
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first