I used work in SOC previously. SIEM is the most important to identify all those zero days virus and persistent attack because it is a day to day monitoring. Vulnerabilities scanning usually run by another team and it was perform on a period basis, eg. monthly, quarterly. With APT, scanning monthly will be too late.
I would say D but this is one where common sense over the book answer probably prevails. The reason the are called APTs is due in part to their ability to go undetected by existing tools like SIEM but that is probably what they are looking for here.
Vulnerability scanning is typically focused on identifying known vulnerabilities and exploits that are publicly available. It may not be able to detect APTs that use new or unknown exploits, or that have been specifically designed to evade detection by security tools. APTs often use advanced evasion techniques, such as encryption, code obfuscation, and anti-virus avoidance techniques, to avoid detection by security tools.
SIEM/XSOAR systems can detect APT. Correct answer: B
upvoted 2 times
...
This section is not available anymore. Please use the main Exam Page.CISM Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
e891cd1
6 months, 3 weeks agoafoo1314
7 months agogigig76
7 months agoLearner76
10 months agosecdoc
1 year ago[Removed]
1 year, 3 months agokaranvp
1 year, 4 months agorichck102
1 year, 4 months agojaiz
1 year, 7 months agoBroesweelies
1 year, 9 months agobaranikumar_v
1 year, 9 months agoCertShooter
1 year, 11 months agoZiggybooboo
1 year, 11 months agotrev0r
2 years agotrev0r
2 years ago