Transit IT wants ongoing proof that SIEM detections fire for common attacker techniques against fare systems. Which control-testing approach fits best?
Select an answer to reveal the explanation.
Short Explanation
BAS is the fire drill that never stops—safe attack replays check whether the SIEM still wakes up. Tabletops alone, a one-off marketing phish, or turning detections off do not give that continuous proof.
Full Explanation
Breach and attack simulation (BAS) repeatedly exercises known techniques and measures whether detections and controls respond as expected. It complements but differs from infrequent tabletops or narrow phishing samples. Disabling detections to reduce noise undermines the very assurance BAS is meant to provide for fare-system monitoring.