exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 257 discussion

Actual exam question from Isaca's CISM
Question #: 257
Topic #: 1
[All CISM Questions]

Which of the following BEST enables the detection of advanced persistent threats (APTs)?

  • A. Vulnerability scanning
  • B. Security information and event management system (SIEM)
  • C. Internet gateway filtering
  • D. Periodic reviews of intrusion prevention system (IPS)
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
e891cd1
6 months, 3 weeks ago
B. Vulnerability scans dont show you Advance Persistent Threats they simply give you the vulnerable components that can be exploited by an APT.
upvoted 1 times
...
afoo1314
7 months ago
Selected Answer: B
I used work in SOC previously. SIEM is the most important to identify all those zero days virus and persistent attack because it is a day to day monitoring. Vulnerabilities scanning usually run by another team and it was perform on a period basis, eg. monthly, quarterly. With APT, scanning monthly will be too late.
upvoted 1 times
...
gigig76
7 months ago
A doesnt sound right, as APT is mostly exploiting zero day vulnerabilities.
upvoted 1 times
...
Learner76
10 months ago
Selected Answer: B
Looking at ISACA review manual. Detection of APT cut across different data source and event. SIEM is the best tool here.
upvoted 3 times
...
secdoc
1 year ago
I would say D but this is one where common sense over the book answer probably prevails. The reason the are called APTs is due in part to their ability to go undetected by existing tools like SIEM but that is probably what they are looking for here.
upvoted 1 times
...
[Removed]
1 year, 3 months ago
D. IPS
upvoted 1 times
...
karanvp
1 year, 4 months ago
Selected Answer: B
Answer B. SIEM
upvoted 1 times
...
richck102
1 year, 4 months ago
B. Security information and event management system (SIEM)
upvoted 1 times
...
jaiz
1 year, 7 months ago
Selected Answer: B
Vulnerability scanning is typically focused on identifying known vulnerabilities and exploits that are publicly available. It may not be able to detect APTs that use new or unknown exploits, or that have been specifically designed to evade detection by security tools. APTs often use advanced evasion techniques, such as encryption, code obfuscation, and anti-virus avoidance techniques, to avoid detection by security tools.
upvoted 2 times
...
Broesweelies
1 year, 9 months ago
Selected Answer: B
SIEM is correct
upvoted 1 times
...
baranikumar_v
1 year, 9 months ago
C. Internet gateway filtering aka firewalls are the best means to guard against APTs
upvoted 1 times
...
CertShooter
1 year, 11 months ago
Correct answer is B. Vuln. scanning is mostly based on known threats. Whereas a SIEM can detect anomalies in system detection mechanisms
upvoted 3 times
...
Ziggybooboo
1 year, 11 months ago
Agreed
upvoted 1 times
...
trev0r
2 years ago
Selected Answer: B
SIEM/XSOAR systems can detect APT. Correct answer: B
upvoted 4 times
...
trev0r
2 years ago
SIEM/XSOAR systems can detect APT. Correct answer: B
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago