certslothcertsloth
CISSP/Topic 08

ISC2 / Professional

Monitoring, Automation and Investigation

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: Correlate signals; constrain automated actions.

Must remember

Collect evidence from identity providers, endpoints, applications, DNS, proxies, firewalls, databases and cloud control planes. Normalize timestamps and retain enough context to connect a user, device, request and resource. Central collection improves correlation but needs access control, integrity protection and retention limits.

SIEM aggregates and correlates security events. SOAR orchestrates response workflows and integrations. EDR supplies endpoint evidence and response; XDR combines multiple detection domains. A dashboard without useful detections or responders is not an effective control.

Data source What it answers
Authentication log Who attempted access, from where, with which outcome?
DNS log Which names did a host request?
Flow record Which endpoints communicated, when and how much?
Packet capture What protocol details/content are visible at this point?
Application audit Which business action or object was affected?
Endpoint telemetry Which process, parent, file or persistence mechanism was involved?

Encrypted traffic can still reveal timing, volume and endpoints while hiding application content. Packet capture location and collection permissions matter. Baselines distinguish ordinary patterns from meaningful deviations; tune rules with feedback instead of disabling noisy detection broadly.

Automation can enrich indicators, create tickets, quarantine endpoints, revoke sessions or enforce configurations. Give automation minimal permissions, bounded targets, tested rollback and human approval for actions with substantial impact. Protect integration credentials and validate untrusted input before passing it to scripts.

Track mean time to detect/respond, coverage, false positives and repeat incidents with clear definitions. A falling alert count can mean better security, broken collection or weaker rules; investigate the reason.

Choose under exam pressure

Requirement Choice and reason
Connect login and endpoint evidence Correlate sources in a SIEM with consistent identifiers/time.
Repeat a well-defined response safely A tested SOAR playbook with scoped credentials.
Need packet-level protocol behavior Capture at an authorized point; consider encryption and privacy.

Traps

  • Logs can contain credentials or personal data.
  • Automating a flawed decision makes the mistake faster and broader.

Active recall

1. SIEM versus SOAR?

SIEM centralizes/correlates evidence; SOAR coordinates response actions and workflows.

2. What do flow logs lack compared with packet capture?

They normally contain connection metadata rather than complete payloads.

3. Why synchronize clocks?

To correlate events and establish a reliable timeline.

4. Why limit a quarantine playbook’s permissions?

A false positive or compromised automation account should not disable unrelated systems.

5. Does fewer alerts prove improvement?

No. Collection or detection may have failed.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.