200-201 Question 86
Select 3A Security Operations Center (SOC) analyst is monitoring a hybrid environment consisting of on-premises hosts, a cloud-based infrastructure, and a corporate network. The analyst notices gaps in their ability to detect certain threats across the environment. Which of the following challenges related to data visibility could be contributing to this issue?
- A
Limited access to telemetry data from cloud service providers
- B
Encryption of network traffic hindering packet inspection
- C
Inconsistent logging configurations on hosts within the environment
- D
High volume of data leading to alert fatigue in the monitoring tools
- E
Use of outdated cybersecurity tools incompatible with modern environments
Show answer and explanation
Correct answers: A, B, C
Explanation
Data visibility challenges in detection arise when there is limited or inconsistent access to critical data sources. In hybrid environments, restricted telemetry from cloud providers, encrypted traffic, and inconsistent host logging can create blind spots for analysts. Understanding and mitigating these visibility gaps is essential for effective threat detection.
- A. Correct.
Cloud service providers often limit or restrict access to raw telemetry data for security and privacy reasons, which can hinder visibility into cloud-based activities.
- B. Correct.
Encrypted network traffic is harder to inspect without decryption capabilities, reducing visibility into potential threats.
- C. Correct.
If logging configurations are not standardized across all hosts, critical information may be missing or inconsistent, leading to detection gaps.
- D. Incorrect.
While alert fatigue is an operational issue, it is not directly related to challenges in data visibility but rather the volume and prioritization of alerts.
- E. Incorrect.
Outdated tools can create security risks, but they are not directly related to the specific challenges of data visibility across network, host, and cloud environments.