セキュリティチームは、セキュリティ侵害に関連する様々な種類のログを手作業で分析するという長時間にわたる作業を経て、その活動が特定の従業員に紐付けられていることを突き止めました。今後、このプロセスを効率化するために、セキュリティチームは以下のどれを実施すべきでしょうか?
正解:A
UEBA (User and Entity Behavior Analytics)uses machine learning and advanced analytics to detect abnormal patterns of behavior, such as unusual access or actions by employees.
Implementing UEBA automates the analysis of logs and identifies suspicious activities, significantly reducing the manual effort required.
OptionB(HSM) is incorrect because a hardware security module is used for secure key management, not log analysis.
OptionC(HIPS) is incorrect because a host intrusion prevention system focuses on preventing attacks on endpoints rather than log analysis.
OptionD(XDR) extends threat detection and response across multiple domains, but it is broader in scope and does not focus specifically on user behavior analysis.
OptionE(OPSEC training) is valuable for educating employees but does not streamline the breach investigation process.
References:
CompTIA CASP+ Exam Objective 4.4: Implement security operations tools and automation solutions.
CASP+ Study Guide, 5th Edition, Chapter 10, Security Operations and Behavioral Analysis.