18. An organization needs to provide space where security administrators can centrally monitor network traffic and events and respond to threats or outages. What should the organization create?
Answer: D
The organization should create a Security Operations Center (SOC).
A Security Operations Center (SOC) is essential for security administrators to centrally monitor network traffic and events, as well as to respond to threats or outages effectively.
A) Emergency response team (ERT)
An Emergency Response Team (ERT) is typically focused on immediate responses to emergencies, such as natural disasters or critical incidents. While they play a crucial role in incident management, they do not specialize in the continuous monitoring of network traffic or security events, making them unsuitable for the organization’s needs.
B) Disaster response team (DRT)
A Disaster Response Team (DRT) is primarily concerned with preparing for and responding to significant disasters. Their focus is on recovery and restoration after an incident, which does not align with the requirement for ongoing monitoring and threat response, thereby rendering them ineffective for the task at hand.
C) Network operations center (NOC)
A Network Operations Center (NOC) is responsible for monitoring and managing network performance and availability. However, it does not specifically focus on security threats and incidents like a SOC does. Thus, while a NOC is important for network management, it does not meet the specific requirement for security monitoring and incident response.
D) Security operations center (SOC)
A Security Operations Center (SOC) is designed for the purpose of monitoring and analyzing security events and incidents in real time. This makes it the ideal choice for the organization as it enables security administrators to detect, analyze, and respond to cybersecurity threats and outages effectively.
Conclusion
Creating a Security Operations Center (SOC) is the most appropriate solution for the organization’s need for centralized monitoring and response to security threats. The other options, including ERT, DRT, and NOC, do not provide the specialized focus on security that a SOC offers, which is critical for ensuring the integrity and safety of the network.