組織は、APT を軽減するための制御を実装して、重要なネットワーク上の機密データを保護する必要があります。現在のポリシーでは、APT の軽減をサポートするガイダンスやプロセスは提供されていません。機密データを保護するために、組織は次のテクノロジーのうちどれを実装する必要がありますか? (2 つ選択してください)。
正解:D,E
IPS and SIEM are technologies that can help secure sensitive data on critical networks by implementing controls to mitigate APTs. IPS stands for Intrusion Prevention System, and it is a device or software that monitors network traffic and blocks or prevents malicious packets or activities based on predefined rules or signatures. IPS can help detect and stop APTs that may try to exploit vulnerabilities or bypass security controls on critical networks. SIEM stands for Security Information and Event Management, and it is a system that collects, correlates, analyzes, and reports security data from various sources, such as logs, alerts, events, etc. SIEM can help identify and respond to APTs that may exhibit anomalous or suspicious behavior patterns on critical networks.