CAS-003 · Question #316
A security technician is incorporating the following requirements in an RFP for a new SIEM: - New security notifications must be dynamically implemented by the SIEM engine - The SIEM must be able to…
The correct answer is B. Machine learning D. Big Data analytics. The three stated SIEM requirements for dynamic threat notifications, baseline anomaly detection, and collective customer threat data all point to machine learning and big data analytics as necessary capabilities.
Question
A security technician is incorporating the following requirements in an RFP for a new SIEM:
- New security notifications must be dynamically implemented by the
SIEM engine
- The SIEM must be able to identify traffic baseline anomalies
- Anonymous attack data from all customers must augment attack
detection and risk scoring Based on the above requirements, which of the following should the SIEM support? (Choose two.)
Options
- AAutoscaling search capability
- BMachine learning
- CMultisensor deployment
- DBig Data analytics
- ECloud-based management
- FCentralized log aggregation
How the community answered
(38 responses)- A11% (4)
- B76% (29)
- C8% (3)
- E3% (1)
- F3% (1)
Why each option
The three stated SIEM requirements for dynamic threat notifications, baseline anomaly detection, and collective customer threat data all point to machine learning and big data analytics as necessary capabilities.
Autoscaling search capability improves query performance and index throughput but does not provide the analytical intelligence needed for dynamic threat detection or anomaly identification.
Machine learning enables the SIEM to dynamically generate and update security notifications by learning from evolving patterns, and it identifies traffic baseline anomalies by modeling normal behavior and flagging statistically significant deviations - directly addressing two of the three stated requirements.
Multisensor deployment is a data collection architecture describing where sensors are placed and does not address dynamic notification updates, anomaly detection algorithms, or shared threat intelligence.
Big data analytics provides the processing infrastructure needed to ingest, correlate, and analyze anonymous attack data contributed from all customers at massive scale, enabling collective threat intelligence that improves risk scoring across the entire customer base.
Cloud-based management describes a delivery and administration model for the SIEM platform but does not itself provide ML-driven detection or big data correlation capabilities.
Centralized log aggregation is a foundational SIEM function for collecting and normalizing data but does not provide the advanced analytics required for dynamic detection or collective threat scoring.
Concept tested: SIEM machine learning and big data analytics capabilities
Source: https://csrc.nist.gov/publications/detail/sp/800-92/final
Topics
Community Discussion
No community discussion yet for this question.