CAS-003 · Question #531
Following a recent and very large corporate merger, the number of log files an SOC needs to review has approximately tripled. The Chief Information Security Officer (CISO) has not been allowed to…
The correct answer is A. SIEM filtering. A SIEM (Security Information and Event Management) system is specifically designed to aggregate, correlate, and filter log data. Configuring SIEM filtering rules allows the SOC to suppress low-value, repetitive, or informational events and surface only actionable alerts…
Question
Following a recent and very large corporate merger, the number of log files an SOC needs to review has approximately tripled. The Chief Information Security Officer (CISO) has not been allowed to hire any more staff for the SOC, but is looking for other ways to automate the log review process so the SOC receives less noise. Which of the following would BEST reduce log noise for the SOC?
Options
- ASIEM filtering
- BMachine learning
- COutsourcing
- DCentralized IPS
How the community answered
(36 responses)- A69% (25)
- B3% (1)
- C8% (3)
- D19% (7)
Explanation
A SIEM (Security Information and Event Management) system is specifically designed to aggregate, correlate, and filter log data. Configuring SIEM filtering rules allows the SOC to suppress low-value, repetitive, or informational events and surface only actionable alerts, directly reducing noise without adding staff. Machine learning (B) could help long-term but requires significant setup and tuning time. Outsourcing (C) redistributes the workload but does not reduce noise and introduces cost and data-sharing concerns. A centralized IPS (D) handles intrusion prevention and generates its own alerts - it does not reduce existing log noise from other sources.
Topics
Community Discussion
No community discussion yet for this question.