NEW
Font size
WorksheetsM4-Q4
Total questions: 10
Worksheet time: 10mins
Which of the following is not a part of SIEM tools?
Sensor
Agent
Collector
Log
Which one is not the part of SIEM application?
Normalization
Risk assessment
Vulnerability Scanning
Real-time monitoring
How does a SIEM tool handle the issue of Completeness of log?
Encryption
Timestamping
Digital Signing
Hashing
The computer security incident response team (CSIRT) of an organization publishes detailed descriptions of recent threats. An IS auditor's GREATEST concern should be that the users may:
Forward the security alert
Implement individual solutions
Fail to understand the threat
Use this information to launch attacks
The main goal of the Security Operation Centre (SOC) is
Detect, analyze and report
Collect, analyze and report
Detect, analyze and respond
Collect, analyze and respond
What is the primary purpose of an incident management program?
Conduct lessons learned sessions
Alert key individuals
Identify and assess incidents
Assign responsibility
SOC shall be ineffective without the support of:
Risk
Budget
Quality
Top management
Phases of an incident management program
Plan, prepare and respond
Prepare, Respond, and follow up
Plan, prepare and follow up
Prepare, plan and respond
Within an Incident Response Management program, the Containment phase aims to
Block the event
Remove the event
Reduce the impact
Rise the event
The basic operation of the SIEM tools, on the logs collected from the devices, is
Correlating the log
Live Correlating the log
Collecting the log
Analyzing the log
