Which practice involves ongoing surveillance to detect abnormal behavior and potential security incidents?

Prepare for the Certified Identity and Access Manager Exam using flashcards and multiple-choice questions. Gain insights into the exam format, practice with real-world scenarios, and ensure your success in becoming a certified professional.

Multiple Choice

Which practice involves ongoing surveillance to detect abnormal behavior and potential security incidents?

Explanation:
Continuous monitoring is the ongoing collection, correlation, and analysis of security telemetry—such as logs, events, and metrics—from systems, networks, and identities to detect abnormal behavior and potential security incidents as they occur. It provides near real-time visibility and alerts when deviations from baselines are observed, enabling faster detection, containment, and investigation. Threat hunting is a proactive, hypothesis-driven search for threats that might evade automated alerts, and it is typically more manual and periodic than continuous monitoring. A password policy sets rules for credential strength and management but does not perform surveillance. Incident response planning outlines the steps to take after an incident is detected, rather than the ongoing detection process.

Continuous monitoring is the ongoing collection, correlation, and analysis of security telemetry—such as logs, events, and metrics—from systems, networks, and identities to detect abnormal behavior and potential security incidents as they occur. It provides near real-time visibility and alerts when deviations from baselines are observed, enabling faster detection, containment, and investigation. Threat hunting is a proactive, hypothesis-driven search for threats that might evade automated alerts, and it is typically more manual and periodic than continuous monitoring. A password policy sets rules for credential strength and management but does not perform surveillance. Incident response planning outlines the steps to take after an incident is detected, rather than the ongoing detection process.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy