ISC2 Certified in Cybersecurity (CC)Security OperationsMedium

A financial institution is under strict regulatory requirements to prove that only authorized personnel have accessed sensitive customer financial records. They need a system that can collect, centralize, and analyze security-relevant data from various sources across their IT infrastructure to provide an auditable trail of access events. Which security operation is best suited to provide this capability?

  1. ASecurity Awareness Training
  2. BLog Management
  3. CVulnerability Scanning
  4. DPenetration Testing
Show answer & explanation

Correct answer: B. Log Management

Log management involves collecting, storing, and analyzing logs from various systems. This capability is essential for creating an auditable trail of access events, which is crucial for regulatory compliance and security investigations in a financial institution.

Why the other options are wrong

  • A. Security awareness training educates users, but doesn't provide an auditable system.
  • C. Vulnerability scanning identifies weaknesses, not access trails.
  • D. Penetration testing simulates attacks, it doesn't build an audit trail.

Log Management

The process of collecting, storing, processing, and analyzing log data from various systems and applications to support security monitoring, auditing, and incident response.

  • Provides an auditable record of activities.
  • Essential for incident response and compliance.
  • Can identify suspicious activities and security breaches.

Memory trick: Logs Leave Legible Life Lines.

More Security Operations questions