Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

CompTIA CAS-005 Exam - Topic 3 Question 30 Discussion

A cybersecurity architect is reviewing the detection and monitoring capabilities for a global company that recently made multiple acquisitions. The architect discovers that the acquired companies use different vendors for detection and monitoring The architect's goal is to:* Create a collection of use cases to help detect known threats* Include those use cases in a centralized library for use across all of the companiesWhich of the following is the best way to achieve this goal?
A) Sigma rules
B) Ariel Query Language
C) UBA rules and use cases
D) TAXII/STIX library

CompTIA CAS-005 Exam - Topic 3 Question 30 Discussion

Actual exam question for CompTIA's CAS-005 exam
Question #: 30
Topic #: 3
[All CAS-005 Questions]

A cybersecurity architect is reviewing the detection and monitoring capabilities for a global company that recently made multiple acquisitions. The architect discovers that the acquired companies use different vendors for detection and monitoring The architect's goal is to:

* Create a collection of use cases to help detect known threats

* Include those use cases in a centralized library for use across all of the companies

Which of the following is the best way to achieve this goal?

Show Suggested Answer Hide Answer
Suggested Answer: A

To create a collection of use cases for detecting known threats and include them in a centralized library for use across multiple companies withdifferent vendors, Sigma rules are the best option. Here's why:

Centralized Rule Management: By using Sigma rules, the cybersecurity architect can create a centralized library of detection rules that can be easily shared and implemented across different detection and monitoring systems used by the acquired companies. This ensures consistency in threat detection capabilities.

Ease of Use and Flexibility: Sigma provides a structured and straightforward format for defining detection logic. It allows for the easy creation, modification, and sharing of rules, facilitating collaboration and standardization across the organization.


Contribute your Thoughts:

0/2000 characters
Belen
3 days ago
C) UBA rules and use cases could work too, but it might be too specific for all companies.
upvoted 0 times
...
Joni
9 days ago
I prefer D) TAXII/STIX library. It standardizes threat intelligence sharing.
upvoted 0 times
...
Alesia
14 days ago
I think A) Sigma rules is the best choice. They're flexible and widely used.
upvoted 0 times
...
Rebbecca
19 days ago
Totally agree with using a centralized library for better efficiency!
upvoted 0 times
...
Tyisha
24 days ago
Wait, can Sigma rules really cover all those different vendors?
upvoted 0 times
...
Alethea
29 days ago
TAXII/STIX library could help with standardization across the board.
upvoted 0 times
...
Desirae
1 month ago
I think UBA rules might be more tailored for specific use cases.
upvoted 0 times
...
Dorothy
1 month ago
Sigma rules are super effective for threat detection!
upvoted 0 times
...
Arlette
1 month ago
I practiced a similar question about detection methods, and I feel like Ariel Query Language was more about querying data rather than creating use cases.
upvoted 0 times
...
Lavonna
2 months ago
UBA rules sound familiar, but I can't recall if they specifically help in creating a centralized use case library.
upvoted 0 times
...
Irving
2 months ago
I think the TAXII/STIX library might be a good option since it focuses on sharing threat intelligence across different systems.
upvoted 0 times
...
Audra
2 months ago
I remember studying Sigma rules for threat detection, but I'm not entirely sure if they would be the best fit for a centralized library.
upvoted 0 times
...

Save Cancel