Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

CompTIA CAS-005 Exam - Topic 3 Question 30 Discussion

A cybersecurity architect is reviewing the detection and monitoring capabilities for a global company that recently made multiple acquisitions. The architect discovers that the acquired companies use different vendors for detection and monitoring The architect's goal is to:* Create a collection of use cases to help detect known threats* Include those use cases in a centralized library for use across all of the companiesWhich of the following is the best way to achieve this goal?
A) Sigma rules
B) Ariel Query Language
C) UBA rules and use cases
D) TAXII/STIX library

CompTIA CAS-005 Exam - Topic 3 Question 30 Discussion

Actual exam question for CompTIA's CAS-005 exam
Question #: 30
Topic #: 3
[All CAS-005 Questions]

A cybersecurity architect is reviewing the detection and monitoring capabilities for a global company that recently made multiple acquisitions. The architect discovers that the acquired companies use different vendors for detection and monitoring The architect's goal is to:

* Create a collection of use cases to help detect known threats

* Include those use cases in a centralized library for use across all of the companies

Which of the following is the best way to achieve this goal?

Show Suggested Answer Hide Answer
Suggested Answer: A

To create a collection of use cases for detecting known threats and include them in a centralized library for use across multiple companies withdifferent vendors, Sigma rules are the best option. Here's why:

Centralized Rule Management: By using Sigma rules, the cybersecurity architect can create a centralized library of detection rules that can be easily shared and implemented across different detection and monitoring systems used by the acquired companies. This ensures consistency in threat detection capabilities.

Ease of Use and Flexibility: Sigma provides a structured and straightforward format for defining detection logic. It allows for the easy creation, modification, and sharing of rules, facilitating collaboration and standardization across the organization.


Contribute your Thoughts:

0/2000 characters

Currently there are no comments in this discussion, be the first to comment!


Save Cancel