FRM Part II · FRM Exam Part II · Cyber-resilience: Range of Practices
A bank's cyber-resilience framework groups its controls into identification, protection, detection, response and recovery, and sustained learning. A security team deploys a security information and event management (SIEM) tool that correlates logs from servers, network devices and endpoints to flag unusual activity. Which function does this tool primarily serve?
A SIEM tool mainly serves the detection function. It collects and correlates logs from servers, networks and endpoints to reveal unusual behaviour and possible intrusions. It does not prevent access, restore systems or catalogue assets, which belong to protection, recovery and identification respectively.
- AProtection, by preventing unauthorised access to systems
- BDetection, by identifying anomalous activity and potential intrusionsCorrect
- CRecovery, by restoring systems after a disruption
- DIdentification, by cataloguing the bank's information assets
Explanation
A SIEM aggregates and correlates logs to surface anomalies and possible intrusions, which is a monitoring and detection capability. It does not itself block access (protection), restore services (recovery) or inventory assets (identification).
Did you get it right without looking?
One question tells you little. A timed set on Cyber-resilience: Range of Practices shows your real accuracy, how long you take and where you lose marks.
More Cyber-resilience: Range of Practices questions
- A bank wants its cyber-resilience strategy to be integrated with enterprise risk management. Which approach best achieves this?
- A bank's board is reviewing its cyber strategy. Management proposes to focus only on preventing every intrusion at the perimeter. Which stat…
- A bank's cyber risk officer reviews the access management programme for its core payment platform. Several system administrators hold perman…
- Which approach best strengthens a bank's identification of emerging cyber threats?
- A bank's cyber-resilience team is building its inventory of assets that support critical business functions. Which activity best reflects so…
- A bank's security team wants to reduce the damage an attacker can do if a single employee's credentials are stolen. Which protective control…