Cisco Certified Support Technician (CCST) CybersecurityNetwork SecurityHard
A security analyst is investigating a suspected data breach. During the investigation, it is discovered that an attacker compromised a server and created a new administrative user account. The attacker then used this new account to exfiltrate sensitive data. Which of the following security controls, if properly implemented and monitored, would have been most effective in detecting the creation of the unauthorized administrative account?
- ANetwork Intrusion Prevention System (NIPS)
- BFile Integrity Monitoring (FIM)
- CSecurity Information and Event Management (SIEM)
- DData Loss Prevention (DLP)
Show answer & explanationAnswer & explanation
Correct answer: C. Security Information and Event Management (SIEM)
A SIEM system collects and aggregates log data from various security devices and applications across the network. It can correlate these events to detect anomalies, such as the creation of a new administrative user account, especially if it's outside of normal operational procedures, and alert security personnel.
Why the other options are wrong
- A. NIPS primarily focuses on blocking known network-based attacks; it's less effective at detecting internal system changes like user account creation.
- B. FIM monitors changes to critical system files and configurations, which could detect changes to user account files, but a SIEM would aggregate this and other logs for a broader correlation.
- D. DLP focuses on preventing sensitive data from leaving the network, which addresses the exfiltration, but not necessarily the initial creation of the unauthorized account.
Security Information and Event Management (SIEM)
A security solution that helps organizations detect, analyze, and respond to security threats by collecting and correlating security event data from across their IT environment.
- Aggregates logs from multiple sources.
- Uses correlation rules to identify potential incidents.
- Provides real-time monitoring and alerting.
Memory trick: SIEM Sees Everything Important.