Skip to content

FRM Part II · FRM Exam Part II · Cyber-resilience: Range of Practices

A bank's cyber-resilience framework groups its controls into identification, protection, detection, response and recovery, and sustained learning. A security team deploys a security information and event management (SIEM) tool that correlates logs from servers, network devices and endpoints to flag unusual activity. Which function does this tool primarily serve?

A SIEM tool mainly serves the detection function. It collects and correlates logs from servers, networks and endpoints to reveal unusual behaviour and possible intrusions. It does not prevent access, restore systems or catalogue assets, which belong to protection, recovery and identification respectively.

  1. AProtection, by preventing unauthorised access to systems
  2. BDetection, by identifying anomalous activity and potential intrusionsCorrect
  3. CRecovery, by restoring systems after a disruption
  4. DIdentification, by cataloguing the bank's information assets

Explanation

A SIEM aggregates and correlates logs to surface anomalies and possible intrusions, which is a monitoring and detection capability. It does not itself block access (protection), restore services (recovery) or inventory assets (identification).

Did you get it right without looking?

One question tells you little. A timed set on Cyber-resilience: Range of Practices shows your real accuracy, how long you take and where you lose marks.

More Cyber-resilience: Range of Practices questions