ExamGecko
Question list
Search
Search

Question 600 - CISM discussion

Report
Export

Which of the following BEST enables an organization to identify and contain security incidents?

A.
Risk assessments
Answers
A.
Risk assessments
B.
Threat modeling
Answers
B.
Threat modeling
C.
Continuous monitoring
Answers
C.
Continuous monitoring
D.
Tabletop exercises
Answers
D.
Tabletop exercises
Suggested answer: C

Explanation:

= Continuous monitoring is the process of collecting, analyzing, and reporting on the security status of an organization's information systems and networks. Continuous monitoring enables an organization to identify and contain security incidents by providing timely and accurate information on the security events, alerts, incidents, and threats that may affect the organization. Continuous monitoring also helps to measure the effectiveness and compliance of the security controls, policies, and procedures that are implemented to protect the organization's information assets. Continuous monitoring can be performed using various tools and methods, such as security information and event management (SIEM) tools, intrusion detection and prevention systems (IDS/IPS), vulnerability scanners, log analyzers, and audit trails.

Reference= CISM Manual1, Chapter 6: Incident Response Planning (IRP), Section 6.2: Continuous Monitoring2

1: https://store.isaca.org/s/store#/store/browse/cat/a2D4w00000Ac6NNEAZ/tiles2:3

asked 01/10/2024
DOMINIC FERNANDEZ
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first