Cisco CyberOps Associate (CBROPS) 200-201Security MonitoringEasy
A security analyst receives an alert from the SIEM indicating 'Large file transfer to an unapproved cloud storage service' originating from a developer's workstation. The alert is triggered by a custom rule that monitors network traffic for connections to known cloud storage domains not on the corporate whitelist. Which type of security monitoring concept does this scenario primarily demonstrate?
- AThreat Intelligence Integration
- BLog Aggregation
- CPolicy Violation Detection
- DVulnerability Management
Show answer & explanationAnswer & explanation
Correct answer: C. Policy Violation Detection
The scenario describes an alert triggered by a 'custom rule' based on a 'corporate whitelist' for 'unapproved cloud storage service'. This directly indicates the detection of an activity that violates predefined organizational security policies.
Why the other options are wrong
- A. Threat intelligence integration involves using external feeds of known malicious indicators, not primarily corporate whitelists for policy enforcement.
- B. Log aggregation is the collection of logs into a central system, not the analysis of policy violations itself.
- D. Vulnerability management focuses on identifying and remediating system weaknesses, not active policy violations by users.
Policy Violation Detection
Policy violation detection is a security monitoring concept where systems are configured to identify and alert on activities that contravene established organizational security policies, rules, or baselines.
- Relies on predefined rules, whitelists, or blacklists.
- Can apply to data access, network connections, software usage, etc.
- Often implemented via SIEM rules, DLP (Data Loss Prevention) systems, or firewalls.
- Aims to enforce compliance and prevent unauthorized actions.
Memory trick: SIEM principles are like the 'rules of engagement' for your security data.