CGRC Continuous Monitoring 4 — Questions and Answers
Question 1: Which tool category provides the broadest visibility into real-time security events across an enterprise for continuous monitoring purposes?
- Vulnerability scanner
- Security Information and Event Management (SIEM) (Correct answer)
- Data Loss Prevention (DLP)
- Web Application Firewall (WAF)
Correct answer: Security Information and Event Management (SIEM)
A SIEM aggregates and correlates log and event data from across the enterprise, providing the broadest real-time visibility for continuous monitoring.
Question 2: In a cloud-shared responsibility model, which continuous monitoring activities remain the customer's responsibility even when using an IaaS provider?
- Physical security of data center facilities
- Hypervisor patch management
- Monitoring of operating systems, applications, and data the customer deploys (Correct answer)
- Network infrastructure availability monitoring
Correct answer: Monitoring of operating systems, applications, and data the customer deploys
In IaaS, the provider secures the underlying infrastructure, but the customer is responsible for monitoring their own OS, applications, and data.
Question 3: A financial services firm must comply with both FISMA and PCI DSS. How should their ISCM program address overlapping control requirements?
- Run separate monitoring programs for each framework to avoid confusion
- Leverage a unified monitoring program that maps common controls to both frameworks simultaneously (Correct answer)
- Prioritize FISMA requirements since it is a federal mandate
- Use PCI DSS as the baseline and supplement with FISMA-specific controls
Correct answer: Leverage a unified monitoring program that maps common controls to both frameworks simultaneously
A unified ISCM program with control mapping reduces duplication of effort by assessing shared controls once and satisfying multiple framework requirements.
Question 4: What is 'configuration drift' in the context of continuous monitoring?
- Gradual degradation of network bandwidth due to increased traffic
- Unauthorized or undocumented changes to system configurations that deviate from the approved baseline (Correct answer)
- Scheduled updates that temporarily alter system settings
- Differences between development and production environment configurations
Correct answer: Unauthorized or undocumented changes to system configurations that deviate from the approved baseline
Configuration drift occurs when systems deviate from their approved secure baseline over time due to unauthorized changes, patches, or incremental modifications.
Question 5: Which stakeholder is ultimately responsible for accepting residual risk identified through continuous monitoring activities?
- Chief Information Security Officer (CISO)
- System Owner
- Authorizing Official (AO) (Correct answer)
- Risk Executive
Correct answer: Authorizing Official (AO)
The Authorizing Official (AO) holds accountability for accepting residual risk and maintaining the system's authorization to operate.
Question 6: An organization's automated scanner reports 200 vulnerabilities, but after analysis only 15 are exploitable given existing compensating controls. This analysis process is called:
- Vulnerability triage and risk contextualization (Correct answer)
- False positive suppression
- Threat hunting
- Control gap analysis
Correct answer: Vulnerability triage and risk contextualization
Vulnerability triage and risk contextualization is the process of evaluating raw scanner findings against the actual threat environment and existing controls to prioritize genuine risks.
Question 7: Which practice ensures that continuous monitoring data remains useful to decision-makers at all organizational tiers?
- Sending raw SIEM logs directly to executive leadership
- Tailoring security status reports to the appropriate level of detail for each audience (Correct answer)
- Consolidating all monitoring data into a single annual report
- Restricting monitoring reports to the security operations team
Correct answer: Tailoring security status reports to the appropriate level of detail for each audience
Effective ISCM communication tailors the level of detail — operational metrics for technical staff, risk summaries for executives — so each audience can act on the information.
Which tool category provides the broadest visibility into real-time security events across an enterprise for continuous monitoring purposes?