ISC2 CISSP Practice Question

A security operations center (SOC) is concerned about sophisticated insider threats and zero-day attacks that might not trigger their existing signature-based security tools. The SOC has recently deployed a new system that establishes a baseline of normal activity for each user and network device. An analyst receives an alert from this system about an accounting user who, despite normally working 9-to-5, has just accessed the customer database at 3 AM and is downloading an unusually large volume of records. Which security solution is BEST suited for generating this type of context-rich, behavior-based alert?

  • Security Information and Event Management (SIEM)

  • Intrusion Prevention System (IPS)

  • Web Application Firewall (WAF)

  • User and Entity Behavior Analytics (UEBA)

ISC2 CISSP
Security Operations
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot