200-201 · Question #369
What is a difference between SIEM and SOAR security systems?
The correct answer is C. SIEM raises alerts in the event of detecting any suspicious activity, and SOAR automates. A core difference is that SIEM systems focus on log aggregation, correlation, and alerting for suspicious activities, while SOAR systems automate incident response workflows and actions.
Question
What is a difference between SIEM and SOAR security systems?
Options
- ASOAR ingests numerous types of logs and event data infrastructure components, and SIEM can
- BSOAR collects and stores security data at a central point and then converts it into actionable
- CSIEM raises alerts in the event of detecting any suspicious activity, and SOAR automates
- DSIEM combines data collecting, standardization, case management, and analytics for a defense-
How the community answered
(44 responses)- B5% (2)
- C93% (41)
- D2% (1)
Why each option
A core difference is that SIEM systems focus on log aggregation, correlation, and alerting for suspicious activities, while SOAR systems automate incident response workflows and actions.
Both SIEM and SOAR (often integrated) can ingest various logs and event data; this statement doesn't highlight a core differentiating function.
Collecting and storing security data at a central point and converting it into actionable insights is a core function of SIEM, not SOAR's primary differentiator, which is automation and orchestration.
SIEM (Security Information and Event Management) systems are primarily designed to collect, aggregate, and analyze log data from various sources to detect and alert on security incidents, while SOAR (Security Orchestration, Automation, and Response) systems focus on automating the execution of security operations tasks and incident response playbooks.
The description for "SIEM combines data collecting, standardization, case management, and analytics" partially describes SIEM, but the choice is incomplete ("for a defense-") and doesn't provide a clear differentiation from SOAR.
Concept tested: Differentiating SIEM and SOAR functionalities
Source: https://learn.microsoft.com/en-us/azure/sentinel/overview
Topics
Community Discussion
No community discussion yet for this question.