ISC2 Certified in Cybersecurity (CC)Security OperationsHard
A cybersecurity incident response team is investigating a sophisticated attack where an attacker has maintained a persistent presence within the network for several weeks. To effectively contain the threat and prevent future occurrences, the team needs to understand the attacker's tactics, techniques, and procedures (TTPs) and identify indicators of compromise (IOCs) across various systems. Which security operations capability is crucial for correlating events and detecting these advanced persistent threats?
- AVulnerability scanning
- BAsset management
- CSecurity monitoring
- DData retention
Show answer & explanationAnswer & explanation
Correct answer: C. Security monitoring
Security monitoring, often leveraging SIEM systems, is crucial for correlating events across diverse systems, detecting anomalies, and identifying IOCs and TTPs associated with advanced persistent threats that might span weeks or months.
Why the other options are wrong
- A. Vulnerability scanning identifies known weaknesses, but not ongoing, sophisticated attacks.
- B. Asset management tracks inventory, not active threat detection or correlation.
- D. Data retention defines how long data is kept, not the active detection of threats.
Security Monitoring
The continuous process of observing and analyzing an organization's systems, networks, and data for security threats and anomalies.
- Detects ongoing threats and attacks.
- Often uses SIEM for correlation.
- Critical for early incident detection and response.
Memory trick: Monitor everything, catch anything.