Cisco CCNP Security Core (SCOR) 350-701Visibility and EnforcementMedium

A security operations center (SOC) analyst is investigating a potential insider threat. They need to monitor all user activity on critical servers, including file access, command execution, and application usage, to detect anomalous behavior. The solution must provide detailed logs and alerts for forensic analysis. Which visibility and enforcement technology is most appropriate for this requirement?

  1. ANetwork Intrusion Detection System (NIDS)
  2. BData Loss Prevention (DLP) system
  3. CSecurity Information and Event Management (SIEM) system
  4. DHost-based Intrusion Detection System (HIDS)
Show answer & explanation

Correct answer: D. Host-based Intrusion Detection System (HIDS)

A Host-based Intrusion Detection System (HIDS) or a host-based endpoint agent is designed to monitor and log activities directly on the server itself, including file access, command execution, and application usage. This provides the granular visibility needed for insider threat detection and forensic analysis, which network-based systems cannot offer.

Why the other options are wrong

  • A. A NIDS monitors network traffic at a specific point and can detect network-based attacks but cannot see internal host activities like file access or command execution on a server.
  • B. A DLP system focuses on preventing sensitive data from leaving the organization, not primarily on monitoring all user activity and command execution on critical servers for anomalous behavior.
  • C. A SIEM system aggregates logs from various sources, including HIDS, but it doesn't generate the host-level activity logs itself. It relies on systems like HIDS to provide that detailed data.

Host-based Intrusion Detection System (HIDS)

A security system that monitors and analyzes activity on an individual host (e.g., server, workstation) to detect suspicious behavior, unauthorized changes, or malicious activity.

  • Provides granular visibility into file access, process execution, and system calls.
  • Crucial for detecting insider threats and advanced persistent threats (APTs).
  • Can detect attacks that bypass network-based defenses.

Memory trick: To catch a sneaky threat, know if you're watching the door or inside the house.

More Visibility and Enforcement questions