Cisco CyberOps Associate (CBROPS) 200-201Security MonitoringEasy

A security analyst receives an alert from the SIEM indicating 'Large file transfer to an unapproved cloud storage service' originating from a developer's workstation. The alert is triggered by a custom rule that monitors network traffic for connections to known cloud storage domains not on the corporate whitelist. Which type of security monitoring concept does this scenario primarily demonstrate?

  1. AThreat Intelligence Integration
  2. BLog Aggregation
  3. CPolicy Violation Detection
  4. DVulnerability Management
Show answer & explanation

Correct answer: C. Policy Violation Detection

The scenario describes an alert triggered by a 'custom rule' based on a 'corporate whitelist' for 'unapproved cloud storage service'. This directly indicates the detection of an activity that violates predefined organizational security policies.

Why the other options are wrong

  • A. Threat intelligence integration involves using external feeds of known malicious indicators, not primarily corporate whitelists for policy enforcement.
  • B. Log aggregation is the collection of logs into a central system, not the analysis of policy violations itself.
  • D. Vulnerability management focuses on identifying and remediating system weaknesses, not active policy violations by users.

Policy Violation Detection

Policy violation detection is a security monitoring concept where systems are configured to identify and alert on activities that contravene established organizational security policies, rules, or baselines.

  • Relies on predefined rules, whitelists, or blacklists.
  • Can apply to data access, network connections, software usage, etc.
  • Often implemented via SIEM rules, DLP (Data Loss Prevention) systems, or firewalls.
  • Aims to enforce compliance and prevent unauthorized actions.

Memory trick: SIEM principles are like the 'rules of engagement' for your security data.

More Security Monitoring questions