CAS-003 · Question #927
A Chief Information Security Officer (CISO) wants to set up a SOC to respond to security threats and events more quickly. The SOC must have the following capacities: - Real-time response…
The correct answer is A. SIEM. A SIEM (Security Information and Event Management) system is the technology that best satisfies all the listed SOC requirements: Real-time response-SIEMs continuously ingest and correlate events, triggering real-time alerts and automated responses. Visualization-SIEM platforms…
Question
A Chief Information Security Officer (CISO) wants to set up a SOC to respond to security threats and events more quickly. The SOC must have the following capacities:
- Real-time response
- Visualization
- Threat intelligence integration
- Cross-referencing from multiple sources
- Deduplication
Which of the following technologies would BEST meet these requirements?
Options
- ASIEM
- BEDR
- COSINT
- DUTM
How the community answered
(28 responses)- A93% (26)
- C4% (1)
- D4% (1)
Explanation
A SIEM (Security Information and Event Management) system is the technology that best satisfies all the listed SOC requirements: Real-time response-SIEMs continuously ingest and correlate events, triggering real-time alerts and automated responses. Visualization-SIEM platforms provide dashboards and graphical representations of security data and trends. Threat intelligence integration-SIEMs can ingest structured threat intelligence feeds (STIX/TAXII) to enrich events with known indicators. Cross-referencing from multiple sources-SIEMs aggregate logs from firewalls, endpoints, cloud services, applications, and identity systems, correlating across all of them. Deduplication-SIEMs normalize and deduplicate raw events to reduce noise and alert fatigue. EDR (B) is limited to endpoint telemetry; OSINT (C) is a data source, not a platform; UTM (D) is a network security appliance, not a SOC analytics and response platform.
Topics
Community Discussion
No community discussion yet for this question.