ExamGecko
Question list
Search
Search

Question 484 - CISM discussion

Report
Export

Which of the following tools provides an incident response team with the GREATEST insight into insider threat activity across multiple systems?

A.
A security information and event management (SIEM) system
Answers
A.
A security information and event management (SIEM) system
B.
An intrusion prevention system (IPS)
Answers
B.
An intrusion prevention system (IPS)
C.
A virtual private network (VPN) with multi-factor authentication (MFA)
Answers
C.
A virtual private network (VPN) with multi-factor authentication (MFA)
D.
An identity and access management (IAM) system
Answers
D.
An identity and access management (IAM) system
Suggested answer: A

Explanation:

A SIEM system is the best tool for providing an incident response team with the greatest insight into insider threat activity across multiple systems because it can collect, correlate, analyze, and report on security events and logs from various sources, such as network devices, servers, applications, and user activities. A SIEM system can also detect and alert on anomalous or suspicious behaviors, such as unauthorized access, data exfiltration, privilege escalation, or policy violations, that may indicate an insider threat. A SIEM system can also support forensic investigations and incident response actions by providing a centralized and comprehensive view of the security posture and incidents.

asked 01/10/2024
Paul A
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first