Cisco CyberOps Associate (CBROPS) 200-201Security ConceptsMedium
A large enterprise uses a centralized logging system to collect security events from all network devices and servers. A security analyst frequently reviews these logs to identify anomalies and potential threats. This practice is a core component of which security program element?
- ASecurity Monitoring
- BSecurity Awareness Training
- CVulnerability Management
- DDisaster Recovery Planning
Show answer & explanationAnswer & explanation
Correct answer: A. Security Monitoring
Security monitoring involves continuously observing and analyzing activity to detect security events, anomalies, and potential threats. Centralized logging and analyst review of logs are fundamental activities within a security monitoring program.
Why the other options are wrong
- B. Security awareness training educates users on security best practices, unrelated to log analysis.
- C. Vulnerability management focuses on identifying, assessing, and remediating weaknesses, not active threat detection from logs.
- D. Disaster recovery planning focuses on business continuity after major disruptions, not day-to-day threat detection.
Security Monitoring
The continuous process of collecting, analyzing, and reviewing data from various sources (e.g., logs, network traffic) to detect and respond to security incidents and anomalies.
- Proactive and reactive threat detection.
- Utilizes tools like SIEM, IDS/IPS, EDR.
- Essential for maintaining situational awareness.
Memory trick: Monitor the gates, manage the risks, train the guards, recover from disasters.