SCP-500 Regulatory Frameworks & Compliance 3 — Questions and Answers
Question 1: A financial institution using SolarWinds needs to prove network device changes were authorized before implementation. Which framework's change management requirement does this address?
- GDPR Article 17
- SOX ITGC controls (Correct answer)
- HIPAA Privacy Rule
- FedRAMP Low baseline
Correct answer: SOX ITGC controls
SOX IT General Controls (ITGC) require authorized change management processes, which NCM's change tracking directly supports.
Question 2: Under PCI DSS Requirement 10, which SolarWinds tool BEST satisfies the need to review logs of all system components daily?
- SolarWinds Log Analyzer (Correct answer)
- SolarWinds NPM
- SolarWinds NCM
- SolarWinds IPAM
Correct answer: SolarWinds Log Analyzer
PCI DSS Requirement 10.6 mandates daily log reviews, and SolarWinds Log Analyzer provides automated log aggregation and alerting to streamline this process.
Question 3: Which NIST Cybersecurity Framework function does SolarWinds Network Performance Monitor MOST directly support?
- Identify
- Detect (Correct answer)
- Respond
- Recover
Correct answer: Detect
NPM continuously monitors network anomalies and generates alerts, directly supporting the NIST CSF 'Detect' function.
Question 4: An organization subject to NERC CIP must track all electronic access to critical cyber assets. Which SolarWinds feature supports this?
- SolarWinds Log Analyzer syslog collection (Correct answer)
- SolarWinds WPM transaction recordings
- SolarWinds Patch Manager deployment history
- SolarWinds VMAN capacity planning
Correct answer: SolarWinds Log Analyzer syslog collection
NERC CIP-006 and CIP-007 require logging of electronic access, which SolarWinds Log Analyzer satisfies by collecting and correlating syslog/SNMP trap data.
Question 5: ISO/IEC 27001 Annex A control A.12.4 requires event logging. How does SolarWinds help organizations meet this control?
- By providing centralized log collection, analysis, and alert-based notification (Correct answer)
- By scanning for open ports on endpoints
- By tracking software license compliance
- By mapping IP address assignments to users
Correct answer: By providing centralized log collection, analysis, and alert-based notification
SolarWinds Log Analyzer and Security Event Manager centralize log collection and enable alerting, directly satisfying ISO 27001 A.12.4 event logging controls.
Question 6: Which SolarWinds product addresses CMMC (Cybersecurity Maturity Model Certification) requirements for configuration management at Maturity Level 2?
- Network Configuration Manager (NCM) (Correct answer)
- Web Help Desk
- Database Performance Analyzer
- IP Address Manager
Correct answer: Network Configuration Manager (NCM)
CMMC Level 2 CM practices require baseline configurations and change control, which NCM provides through automated config backup and policy enforcement.
Question 7: Under GLBA (Gramm-Leach-Bliley Act), financial institutions must implement safeguards to protect customer information. Which SolarWinds capability MOST directly supports this?
- Security Event Manager correlation rules detecting unauthorized data access (Correct answer)
- NPM traffic throughput graphing
- SAM CPU utilization polling
- IPAM DHCP lease tracking
Correct answer: Security Event Manager correlation rules detecting unauthorized data access
SolarWinds Security Event Manager detects and alerts on unauthorized access attempts, directly supporting GLBA Safeguards Rule requirements.
A financial institution using SolarWinds needs to prove network device changes were authorized before implementation.
Which framework's change management requirement does this address?