What is Continuous Monitoring?
Final Quiz
Connecting to LMS...
Progress: in progress
Assessment
1. What is continuous monitoring?
A. A one-time security review performed only before launch.
B. An ongoing process for maintaining awareness of security posture, changes, vulnerabilities, threats, controls, and risk.
C. A replacement for all security controls.
D. A dashboard that never requires human review.
2. Why is continuous monitoring needed after a system is deployed?
A. Security posture can change as assets, identities, configurations, vulnerabilities, threats, and business use change.
B. Deployed systems can no longer change.
C. Monitoring guarantees no incidents can happen.
D. Monitoring replaces remediation.
3. What should monitoring scope be based on?
A. Only the easiest systems to monitor.
B. Risk, criticality, data sensitivity, exposure, business context, and operational needs.
C. Dashboard color preferences.
D. Random asset selection.
4. Which item is commonly monitored in a security program?
A. Office furniture placement.
B. Application logo size.
C. Vulnerabilities, identities, configurations, logs, assets, changes, and control evidence.
D. Employee lunch preferences.
5. What is configuration drift?
A. A change from an approved or expected configuration state.
B. A graphic design style.
C. A password reset email.
D. A course navigation feature.
6. Why do privileged identities deserve close monitoring?
A. They are never targeted.
B. They cannot affect systems.
C. They are unrelated to risk.
D. They usually have access that can create high-impact security or operational changes.
7. What is telemetry?
A. A legal contract only.
B. Security-relevant data generated by systems, applications, identities, networks, or cloud services.
C. A password hashing method.
D. A static course image.
8. Why does log retention matter?
A. Retention removes the need for incident response.
B. Retention guarantees every alert is correct.
C. Retention affects how far back investigators, auditors, and operators can reconstruct activity.
D. Retention only affects user interface themes.
9. What is alert fatigue?
A. A condition where excessive low-value alerts make meaningful signals easier to identify.
B. A condition where excessive or low-quality alerts overwhelm reviewers and reduce response effectiveness.
C. A vulnerability patching method.
D. A backup encryption setting.
10. What is a false positive?
A. An alert or finding that reports a problem that did not occur as described.
B. A real incident that was missed.
C. A completed remediation ticket.
D. A required backup test.
11. What is a false negative?
A. A report formatting issue.
B. A duplicate asset tag.
C. A planned maintenance window.
D. A relevant problem or event that monitoring fails to detect.
12. Why is alert triage important?
A. It replaces all logging.
B. It proves every alert is an incident.
C. It helps determine severity, context, confidence, ownership, and whether escalation or response is needed.
D. It eliminates the need for documentation.
13. What does control monitoring examine?
A. Whether security controls remain implemented, operating, reviewed, and supported by evidence.
B. Whether the company logo changed.
C. Whether training slides have enough icons.
D. Whether all alerts should be ignored.
14. Why should compliance evidence reflect real operations?
A. Evidence is only decorative.
B. Evidence should be invented when missing.
C. Evidence replaces security engineering.
D. Evidence should support claims about what is actually implemented, reviewed, and operating.
15. What should happen when monitoring identifies a meaningful issue?
A. It should automatically prove compromise.
B. It should always be deleted.
C. It should be ignored until the next annual review.
D. It should be connected to ownership, triage, remediation, risk acceptance, or escalation as appropriate.
16. Which statement best summarizes effective continuous monitoring?
A. Continuous monitoring means collecting every possible log without review.
B. Continuous monitoring is only useful for compliance paperwork.
C. Continuous monitoring is a risk-based, evidence-driven process that connects security signals to decisions, remediation, reporting, and improvement.
D. Continuous monitoring replaces all incident response and vulnerability management.
Submit Quiz
Previous