ExamGecko
Question list
Search
Search

Question 372 - CISM discussion

Report
Export

Which of the following is the BEST way lo monitor for advanced persistent threats (APT) in an organization?

A.
Network with peers in the industry to share information.
Answers
A.
Network with peers in the industry to share information.
B.
Browse the Internet to team of potential events
Answers
B.
Browse the Internet to team of potential events
C.
Search for anomalies in the environment
Answers
C.
Search for anomalies in the environment
D.
Search for threat signatures in the environment.
Answers
D.
Search for threat signatures in the environment.
Suggested answer: C

Explanation:

An advanced persistent threat (APT) is a stealthy and sophisticated attack that aims to compromise and maintain access to a target network or system over a long period of time, often for espionage or sabotage purposes. APTs are difficult to detect by conventional security tools, such as antivirus or firewalls, that rely on signatures or rules to identify threats. Therefore, the best way to monitor for APTs is to search for anomalies in the environment, such as unusual network traffic, user behavior, file activity, or system configuration changes, that may indicate a compromise or an ongoing attack.

Reference: https://www.isaca.org/credentialing/cism https://www.nist.gov/publications/information-security-handbook-guide-managers

asked 01/10/2024
Vincent Meuldijk
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first