ISC2 Certified in Cybersecurity (CC)Security OperationsHard

A critical infrastructure organization operates a Supervisory Control and Data Acquisition (SCADA) system that controls essential services. Due to the high impact of any disruption, they require continuous, real-time analysis of network traffic, system logs, and security events from their industrial control systems (ICS) to detect anomalies and potential threats immediately. Which security operation is designed to provide this continuous, real-time threat detection capability?

  1. AVulnerability Scanning
  2. BSecurity Monitoring
  3. CSecurity Audits
  4. DSecurity Assessments
Show answer & explanation

Correct answer: B. Security Monitoring

Security monitoring involves the continuous observation and analysis of an organization's systems, networks, and data to detect security incidents, anomalies, and threats in real-time. This is essential for critical infrastructure like SCADA systems where immediate detection is paramount.

Why the other options are wrong

  • A. Vulnerability scanning identifies weaknesses at a point in time, it's not continuous threat detection.
  • C. Security audits are periodic reviews, not continuous real-time detection.
  • D. Security assessments are broader evaluations, not continuous real-time threat detection.

Security Monitoring

The continuous process of observing and analyzing an organization's systems, networks, and data for security-related events, anomalies, and potential threats.

  • Provides real-time threat detection.
  • Utilizes tools like SIEM and IDS/IPS.
  • Crucial for incident response and proactive defense.

Memory trick: Monitoring Makes Malicious Moves Manifest.

More Security Operations questions