Chapter 8: Security Management
questions and answers rated A+
Which of the following components are the SIEM's way of letting the IT team know that a pre-
established parameter is not within the acceptable range? - correct answer ✔✔ Alerts
Most SIEM implementations start by installing which tool on network devices? - correct answer
✔✔ Collection agent
Where can you find a quick overview of your monitored system's current state? - correct answer
✔✔ Dashboard
Which of the following is true about a SIEM's Security Information Management? - correct
answer ✔✔ Provides long-term storage of collected data to meet government compliance
requirements
Which of the following is the term used for an IP address that's been flagged for suspicious or
malicious activity? - correct answer ✔✔ Known bad
Where are network device log files stored by default? - correct answer ✔✔ On the local device
Which SIEM function provides long-term storage of collected data to meet government
compliance requirements? - correct answer ✔✔ Retention
Which of the following is true about rule-writing? - correct answer ✔✔ Rules could be as simple
as looking for unsuccessful logins or could include more complex behavioral patterns.
, Which of the following is a SIEM collection tool that's used to search and analyze large
collections of data in multiple formats? - correct answer ✔✔ Splunk
Which of the following BEST describes a SIEM system? - correct answer ✔✔ Is sold as a software
application or as a stand-alone security appliance
A security analyst is responsible for detecting and responding to security incidents in the
organization. The security analyst has decided to implement a security orchestration,
automation, and response (SOAR) platform.
What is the primary purpose of using a SOAR platform in this scenario? - correct answer ✔✔ To
automate incident responses
What is the philosophy behind DevSecOps? - correct answer ✔✔ Everyone on the development
team should be responsible for security.
Which of the following BEST describes workflow orchestration? - correct answer ✔✔ A
collection of tasks that are performed in a logical sequence as efficiently as possible.
As a security administrator for your company, you are working with the network engineer to
find a graphical user interface that allows network administrators to manage their entire
network from one place.
Which of the following orchestration types would meet your requirements? - correct answer
✔✔ Single pane of glass orchestration
In a large organization, the security team struggles to track all the security tools used across
different departments. They want to streamline their security operations by integrating all the
security tools into a central dashboard.
Which solution should the team consider to achieve this goal? - correct answer ✔✔ Application
programming interface (API)
questions and answers rated A+
Which of the following components are the SIEM's way of letting the IT team know that a pre-
established parameter is not within the acceptable range? - correct answer ✔✔ Alerts
Most SIEM implementations start by installing which tool on network devices? - correct answer
✔✔ Collection agent
Where can you find a quick overview of your monitored system's current state? - correct answer
✔✔ Dashboard
Which of the following is true about a SIEM's Security Information Management? - correct
answer ✔✔ Provides long-term storage of collected data to meet government compliance
requirements
Which of the following is the term used for an IP address that's been flagged for suspicious or
malicious activity? - correct answer ✔✔ Known bad
Where are network device log files stored by default? - correct answer ✔✔ On the local device
Which SIEM function provides long-term storage of collected data to meet government
compliance requirements? - correct answer ✔✔ Retention
Which of the following is true about rule-writing? - correct answer ✔✔ Rules could be as simple
as looking for unsuccessful logins or could include more complex behavioral patterns.
, Which of the following is a SIEM collection tool that's used to search and analyze large
collections of data in multiple formats? - correct answer ✔✔ Splunk
Which of the following BEST describes a SIEM system? - correct answer ✔✔ Is sold as a software
application or as a stand-alone security appliance
A security analyst is responsible for detecting and responding to security incidents in the
organization. The security analyst has decided to implement a security orchestration,
automation, and response (SOAR) platform.
What is the primary purpose of using a SOAR platform in this scenario? - correct answer ✔✔ To
automate incident responses
What is the philosophy behind DevSecOps? - correct answer ✔✔ Everyone on the development
team should be responsible for security.
Which of the following BEST describes workflow orchestration? - correct answer ✔✔ A
collection of tasks that are performed in a logical sequence as efficiently as possible.
As a security administrator for your company, you are working with the network engineer to
find a graphical user interface that allows network administrators to manage their entire
network from one place.
Which of the following orchestration types would meet your requirements? - correct answer
✔✔ Single pane of glass orchestration
In a large organization, the security team struggles to track all the security tools used across
different departments. They want to streamline their security operations by integrating all the
security tools into a central dashboard.
Which solution should the team consider to achieve this goal? - correct answer ✔✔ Application
programming interface (API)