Question 1 of 30
The monitoring system demonstrates a significant gap in detecting sophisticated, multi-stage attacks that originate internally or bypass perimeter defenses. Considering the need for comprehensive threat visibility and efficient resource utilization, which of the following architectural approaches would best address this deficiency while adhering to robust security principles?
Implement a layered security monitoring strategy that integrates network intrusion detection/prevention systems at critical points, aggregates logs from key network devices and servers, and utilizes endpoint detection and response (EDR) solutions, all feeding into a Security Information and Event Management (SIEM) system for correlation and intelligent alerting.
Deploy extensive perimeter-based intrusion detection systems (IDS) across all network ingress and egress points, focusing on deep packet inspection for known malicious signatures.
Establish a centralized log management system that collects all available logs from every device on the network without implementing advanced correlation or threat intelligence features.
Prioritize the deployment of advanced endpoint detection and response (EDR) agents on all workstations and servers, assuming that network-level anomalies will be implicitly detected by endpoint behavior.

Preparing for CompTIA CySA+ Exam? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free