SCP-500 Regulatory Frameworks & Compliance 5 — Questions and Answers
Question 1: A SolarWinds administrator needs to demonstrate that privileged access to network devices is monitored per CIS Control 6. Which tool provides this evidence?
- NCM audit logs of device login activity (Correct answer)
- NPM interface availability graphs
- WPM user journey recordings
- VMAN virtual machine capacity reports
Correct answer: NCM audit logs of device login activity
CIS Control 6 requires controlled use of administrative privileges, and NCM logs all authenticated access and changes to network devices.
Question 2: Under DORA (Digital Operational Resilience Act) for financial entities, ICT risk management must include monitoring of third-party service providers. Which SolarWinds feature supports this?
- NPM monitoring of external service endpoints and SLAs (Correct answer)
- NCM device configuration backups
- IPAM DHCP scope management
- SAM Windows event log collection
Correct answer: NPM monitoring of external service endpoints and SLAs
NPM can monitor availability and performance of third-party service endpoints, providing the continuous ICT risk visibility DORA requires.
Question 3: Which SolarWinds product helps organizations meet NIST 800-171 requirement 3.3.1 (creating and retaining system audit logs)?
- SolarWinds Security Event Manager (Correct answer)
- SolarWinds Patch Manager
- SolarWinds Web Help Desk
- SolarWinds DameWare Remote Everywhere
Correct answer: SolarWinds Security Event Manager
SolarWinds Security Event Manager collects, retains, and analyzes audit logs from systems across the environment to satisfy NIST 800-171 audit logging requirements.
Question 4: An auditor asks for proof that firewall rule changes were reviewed and approved. Which SolarWinds workflow BEST provides this evidence?
- NCM change management workflow with approval gates and audit trail (Correct answer)
- NPM topology map exports
- IPAM subnet documentation
- SAM application dependency maps
Correct answer: NCM change management workflow with approval gates and audit trail
NCM's change management workflow captures approval gates, timestamps, and the identity of who made each change, providing complete firewall change audit evidence.
Question 5: Which regulation specifically requires covered entities to have a formal sanctions policy for employees who violate security policies, which SolarWinds alerting can help enforce?
- HIPAA Security Rule §164.308(a)(1)(ii)(C) (Correct answer)
- PCI DSS Requirement 12.3
- SOX Section 404
- GDPR Article 83
Correct answer: HIPAA Security Rule §164.308(a)(1)(ii)(C)
HIPAA Security Rule §164.308(a)(1)(ii)(C) requires a sanctions policy for security violations, and SolarWinds SEM alerts can document the violations triggering those sanctions.
Question 6: SolarWinds NCM's 'Config Diff' feature MOST directly supports which compliance audit activity?
- Demonstrating unauthorized changes were detected and documented (Correct answer)
- Measuring network latency between sites
- Tracking IP address utilization trends
- Monitoring application response times
Correct answer: Demonstrating unauthorized changes were detected and documented
Config Diff compares current and baseline configurations to identify unauthorized changes, which auditors require as evidence of change control monitoring.
Question 7: When mapping SolarWinds capabilities to the NIST CSF 'Protect' function, which product BEST addresses PR.AC-4 (access permissions managed)?
- SolarWinds Access Rights Manager (ARM) (Correct answer)
- SolarWinds Network Performance Monitor
- SolarWinds Server & Application Monitor
- SolarWinds IP Address Manager
Correct answer: SolarWinds Access Rights Manager (ARM)
SolarWinds Access Rights Manager manages and audits user access permissions across AD, file shares, and Exchange, directly supporting NIST CSF PR.AC-4.
A SolarWinds administrator needs to demonstrate that privileged access to network devices is monitored per CIS Control 6.
Which tool provides this evidence?