Cisco CCNP Security Core (SCOR) 350-701Security ConceptsHard

A security analyst is conducting a post-incident review after a successful ransomware attack. The review reveals that the organization lacked a clear understanding of its critical assets, their dependencies, and the business impact of their compromise. This deficiency significantly hampered effective incident response and prioritization. To prevent similar issues in the future, the organization needs to strengthen its efforts in which key area of security operations?

  1. ASecurity reporting
  2. BAsset management
  3. CThreat intelligence gathering
  4. DSecurity awareness training
Show answer & explanation

Correct answer: B. Asset management

The core issue identified was a lack of 'clear understanding of its critical assets, their dependencies, and the business impact'. This is a fundamental aspect of 'asset management' within security operations, which involves identifying, classifying, and tracking all organizational assets.

Why the other options are wrong

  • A. Security reporting communicates status, not the inventory of assets.
  • C. Threat intelligence focuses on external threats, not internal asset understanding.
  • D. Awareness training educates users, not inventories assets.

Asset Management (Security)

The systematic process of identifying, classifying, inventorying, and tracking an organization's critical information assets to ensure appropriate protection and risk management.

  • Foundation for risk assessments, incident response, and compliance.
  • Includes hardware, software, data, intellectual property, and services.
  • Helps prioritize security efforts based on asset criticality and value.

Memory trick: Know what you have to know what to protect: Asset Management.

More Security Concepts questions