Cisco CyberOps Associate (CBROPS) 200-201Security ConceptsMedium

A large enterprise uses a centralized logging system to collect security events from all network devices and servers. A security analyst frequently reviews these logs to identify anomalies and potential threats. This practice is a core component of which security program element?

  1. ASecurity Monitoring
  2. BSecurity Awareness Training
  3. CVulnerability Management
  4. DDisaster Recovery Planning
Show answer & explanation

Correct answer: A. Security Monitoring

Security monitoring involves continuously observing and analyzing activity to detect security events, anomalies, and potential threats. Centralized logging and analyst review of logs are fundamental activities within a security monitoring program.

Why the other options are wrong

  • B. Security awareness training educates users on security best practices, unrelated to log analysis.
  • C. Vulnerability management focuses on identifying, assessing, and remediating weaknesses, not active threat detection from logs.
  • D. Disaster recovery planning focuses on business continuity after major disruptions, not day-to-day threat detection.

Security Monitoring

The continuous process of collecting, analyzing, and reviewing data from various sources (e.g., logs, network traffic) to detect and respond to security incidents and anomalies.

  • Proactive and reactive threat detection.
  • Utilizes tools like SIEM, IDS/IPS, EDR.
  • Essential for maintaining situational awareness.

Memory trick: Monitor the gates, manage the risks, train the guards, recover from disasters.

More Security Concepts questions