nerdexam
CompTIA

CAS-003 · Question #531

Following a recent and very large corporate merger, the number of log files an SOC needs to review has approximately tripled. The Chief Information Security Officer (CISO) has not been allowed to…

The correct answer is A. SIEM filtering. A SIEM (Security Information and Event Management) system is specifically designed to aggregate, correlate, and filter log data. Configuring SIEM filtering rules allows the SOC to suppress low-value, repetitive, or informational events and surface only actionable alerts…

Enterprise Security Operations

Question

Following a recent and very large corporate merger, the number of log files an SOC needs to review has approximately tripled. The Chief Information Security Officer (CISO) has not been allowed to hire any more staff for the SOC, but is looking for other ways to automate the log review process so the SOC receives less noise. Which of the following would BEST reduce log noise for the SOC?

Options

  • ASIEM filtering
  • BMachine learning
  • COutsourcing
  • DCentralized IPS

How the community answered

(36 responses)
  • A
    69% (25)
  • B
    3% (1)
  • C
    8% (3)
  • D
    19% (7)

Explanation

A SIEM (Security Information and Event Management) system is specifically designed to aggregate, correlate, and filter log data. Configuring SIEM filtering rules allows the SOC to suppress low-value, repetitive, or informational events and surface only actionable alerts, directly reducing noise without adding staff. Machine learning (B) could help long-term but requires significant setup and tuning time. Outsourcing (C) redistributes the workload but does not reduce noise and introduces cost and data-sharing concerns. A centralized IPS (D) handles intrusion prevention and generates its own alerts - it does not reduce existing log noise from other sources.

Topics

#SIEM filtering#log management#SOC operations#alert noise reduction

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice