312-39 · Question #98
A health corporation is implementing a SIEM solution to improve detection and response and comply with HIPAA requirements. They need the SIEM to efficiently collect, analyze, and correlate security…
The correct answer is C. Log management and security analytics. To meet the stated needs-collecting, analyzing, correlating, and alerting-log management and security analytics is the core SIEM capability set. Log management covers ingestion, parsing, normalization, storage, retention, and search. Security analytics covers detection rules…
Question
A health corporation is implementing a SIEM solution to improve detection and response and comply with HIPAA requirements. They need the SIEM to efficiently collect, analyze, and correlate security events from network devices, servers, and security applications, and generate timely alerts for potential HIPAA violations. Which capability is needed to meet these needs?
Options
- AThreat hunting and intelligence
- BCentralized SIEM implementation
- CLog management and security analytics
- DLog collection through agents
How the community answered
(48 responses)- A4% (2)
- C94% (45)
- D2% (1)
Explanation
To meet the stated needs-collecting, analyzing, correlating, and alerting-log management and security analytics is the core SIEM capability set. Log management covers ingestion, parsing, normalization, storage, retention, and search. Security analytics covers detection rules, correlations, behavioral analytics, alerting, and dashboards that turn raw events into actionable incidents. These functions are essential for identifying potential HIPAA violations (unauthorized access, anomalous data access, improper privilege use) and producing timely alerts and audit evidence. “Centralized SIEM implementation” is an architectural statement rather than a capability; centralization helps but doesn’t describe the functions needed. “Log collection through agents” is one ingestion method and is important for coverage, but by itself it doesn’t provide analysis and correlation. Threat hunting and intelligence are valuable enhancements, but the requirement described is the baseline SIEM function: manage logs and apply analytics to detect and alert. From a SOC standpoint, this also supports compliance because strong log management with tuned analytics enables both real-time incident response and retrospective investigations with reliable retention and audit trails.
Topics
Community Discussion
No community discussion yet for this question.