CompTIA SecurityX (CAS-005)Security OperationsEasy
A security analyst is investigating a suspected insider threat. They discover that a privileged user account was used to access sensitive customer data outside of business hours from an unusual geographic location. The organization's security policy states that all access to sensitive data must be logged, and any anomalous access patterns should trigger an alert for immediate review. Which of the following best describes the primary security control that failed to prevent this incident?
- ASecurity Information and Event Management (SIEM)
- BEndpoint Detection and Response (EDR)
- CIntrusion Prevention System (IPS)
- DData Loss Prevention (DLP)
Show answer & explanationAnswer & explanation
Correct answer: A. Security Information and Event Management (SIEM)
The scenario describes the detection of anomalous access patterns by correlating logs, which is a core function of a SIEM system. A SIEM collects, aggregates, and analyzes log data from various sources to identify security incidents and policy violations.
Why the other options are wrong
- B. EDR focuses on endpoint activity and may not have the holistic view of user access patterns across different systems and geographic locations.
- C. IPS typically focuses on network-based intrusion detection and prevention, and would not directly monitor or alert on user access patterns to data stores.
- D. DLP primarily focuses on preventing sensitive data from leaving the organization's control, not necessarily on detecting anomalous access to it internally.
SIEM
Security Information and Event Management (SIEM) systems combine security information management (SIM) and security event management (SEM) functions into one security management system.
- Collects logs and security alerts from various sources.
- Aggregates and normalizes data for analysis.
- Identifies and alerts on security incidents and policy violations.
Memory trick: SIEM Sees Everything, Instantly Alerts.