nerdexam
CompTIA

CAS-003 · Question #316

A security technician is incorporating the following requirements in an RFP for a new SIEM: - New security notifications must be dynamically implemented by the SIEM engine - The SIEM must be able to…

The correct answer is B. Machine learning D. Big Data analytics. The three stated SIEM requirements for dynamic threat notifications, baseline anomaly detection, and collective customer threat data all point to machine learning and big data analytics as necessary capabilities.

Enterprise Security Operations

Question

A security technician is incorporating the following requirements in an RFP for a new SIEM:

  • New security notifications must be dynamically implemented by the

SIEM engine

  • The SIEM must be able to identify traffic baseline anomalies
  • Anonymous attack data from all customers must augment attack

detection and risk scoring Based on the above requirements, which of the following should the SIEM support? (Choose two.)

Options

  • AAutoscaling search capability
  • BMachine learning
  • CMultisensor deployment
  • DBig Data analytics
  • ECloud-based management
  • FCentralized log aggregation

How the community answered

(38 responses)
  • A
    11% (4)
  • B
    76% (29)
  • C
    8% (3)
  • E
    3% (1)
  • F
    3% (1)

Why each option

The three stated SIEM requirements for dynamic threat notifications, baseline anomaly detection, and collective customer threat data all point to machine learning and big data analytics as necessary capabilities.

AAutoscaling search capability

Autoscaling search capability improves query performance and index throughput but does not provide the analytical intelligence needed for dynamic threat detection or anomaly identification.

BMachine learningCorrect

Machine learning enables the SIEM to dynamically generate and update security notifications by learning from evolving patterns, and it identifies traffic baseline anomalies by modeling normal behavior and flagging statistically significant deviations - directly addressing two of the three stated requirements.

CMultisensor deployment

Multisensor deployment is a data collection architecture describing where sensors are placed and does not address dynamic notification updates, anomaly detection algorithms, or shared threat intelligence.

DBig Data analyticsCorrect

Big data analytics provides the processing infrastructure needed to ingest, correlate, and analyze anonymous attack data contributed from all customers at massive scale, enabling collective threat intelligence that improves risk scoring across the entire customer base.

ECloud-based management

Cloud-based management describes a delivery and administration model for the SIEM platform but does not itself provide ML-driven detection or big data correlation capabilities.

FCentralized log aggregation

Centralized log aggregation is a foundational SIEM function for collecting and normalizing data but does not provide the advanced analytics required for dynamic detection or collective threat scoring.

Concept tested: SIEM machine learning and big data analytics capabilities

Source: https://csrc.nist.gov/publications/detail/sp/800-92/final

Topics

#SIEM capabilities#machine learning#big data analytics#threat detection

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice