ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 244 - CAS-004 discussion

Report
Export

city government's IT director was notified by the City council that the following cybersecurity requirements must be met to be awarded a large federal grant:

+ Logs for all critical devices must be retained for 365 days to enable monitoring and threat hunting.

+ All privileged user access must be tightly controlled and tracked to mitigate compromised accounts.

+ Ransomware threats and zero-day vulnerabilities must be quickly identified.

Which of the following technologies would BEST satisfy these requirements? (Select THREE).

A.
Endpoint protection
Answers
A.
Endpoint protection
B.
Log aggregator
Answers
B.
Log aggregator
C.
Zero trust network access
Answers
C.
Zero trust network access
D.
PAM
Answers
D.
PAM
E.
Cloud sandbox
Answers
E.
Cloud sandbox
F.
SIEM
Answers
F.
SIEM
G.
NGFW
Answers
G.
NGFW
Suggested answer: B, D, F

Explanation:

B) Log aggregator: A log aggregator is a tool that collects, parses, and stores logs from various sources, such as devices, applications, servers, etc.A log aggregator can help meet the requirement of retaining logs for 365 days by providing a centralized and scalable storage solution1.

D) PAM: PAM stands for privileged access management. It is a technology that controls and monitors the access of privileged users (such as administrators) to critical systems and data. PAM can help meet the requirement of controlling and tracking privileged user access by enforcing policies such as least privilege, multifactor authentication, password rotation, session recording, etc. .

F) SIEM: SIEM stands for security information and event management. It is a technology that analyzes and correlates logs from various sources to detect and respond to security incidents. SIEM can help meet the requirement of identifying ransomware threats and zero-day vulnerabilities by providing real-time alerts, threat intelligence feeds, incident response workflows, etc. .


asked 02/10/2024
Rahul Biradavolu
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first