規制の厳しい企業において、セキュリティインシデントの影響を最小限に抑えるため、サイバーセキュリティアナリストは組織のクラウドサービスに監査設定を構成しました。アナリストが構成したセキュリティ制御は次のうちどれですか?
正解:D
Audit settings provide visibility into user actions and system events. These are classified asdetective controlsbecause they enable the detection of anomalies, policy violations, or unauthorized access by generating logs or alerts. They do not prevent actions (Preventive) or reverse harm (Corrective), nor do they provide policy guidance (Directive).
# Reference: CompTIA CySA+ All-in-One by Mya Heath, Chapter 13, "Vulnerability Handling and Response" - Control Types and Functions.
# Objective: 2.5 - Explain the importance of prioritization, remediation, and mitigation of vulnerabilities.