CISSP Practice Question: A financial institution needs to improve detection of unauthorized access and ensure…
Correct Answer: A. Implement a Security Information and Event Management (SIEM) system to automate log analysis and correlate security events.
Explanation (CISSP Manager Logic):
Automation is essential for scaling security operations and meeting the continuous monitoring requirements of financial regulations. A SIEM provides centralized visibility, transforming raw log data into actionable intelligence for proactive, real-time incident detection.
By implementing a SIEM, you:
- Reduce Mean Time to Detect (MTTD) through automated correlation.
- Ensure consistent compliance with regulatory audit and monitoring mandates.
- Optimize resource allocation by shifting personnel from manual sifting to strategic response.
While the other options are relevant, they fall short because:
- B: Manual reviews are unscalable, prone to human error, and cannot provide real-time alerting.
- C: Segmentation is a preventive control that reduces the attack surface but does not address the log analysis visibility gap.
- D: User reporting is a subjective, unreliable layer of defense that cannot replace technical detection mechanisms.
Think like a manager:
Prioritize high-ROI solutions that leverage automation to provide a centralized "single pane of glass" for rapid, data-driven decision-making.
Ready to find out if you'd pass?
5,000+ expert-calibrated questions, adaptive CAT mock exams, and gap analysis that shows exactly what to study next.
Try 5 free questions Start 7-day free trial