nerdexam
CompTIA

CAS-003 · Question #927

A Chief Information Security Officer (CISO) wants to set up a SOC to respond to security threats and events more quickly. The SOC must have the following capacities: - Real-time response…

The correct answer is A. SIEM. A SIEM (Security Information and Event Management) system is the technology that best satisfies all the listed SOC requirements: Real-time response-SIEMs continuously ingest and correlate events, triggering real-time alerts and automated responses. Visualization-SIEM platforms…

Enterprise Security Operations

Question

A Chief Information Security Officer (CISO) wants to set up a SOC to respond to security threats and events more quickly. The SOC must have the following capacities:

  • Real-time response
  • Visualization
  • Threat intelligence integration
  • Cross-referencing from multiple sources
  • Deduplication

Which of the following technologies would BEST meet these requirements?

Options

  • ASIEM
  • BEDR
  • COSINT
  • DUTM

How the community answered

(28 responses)
  • A
    93% (26)
  • C
    4% (1)
  • D
    4% (1)

Explanation

A SIEM (Security Information and Event Management) system is the technology that best satisfies all the listed SOC requirements: Real-time response-SIEMs continuously ingest and correlate events, triggering real-time alerts and automated responses. Visualization-SIEM platforms provide dashboards and graphical representations of security data and trends. Threat intelligence integration-SIEMs can ingest structured threat intelligence feeds (STIX/TAXII) to enrich events with known indicators. Cross-referencing from multiple sources-SIEMs aggregate logs from firewalls, endpoints, cloud services, applications, and identity systems, correlating across all of them. Deduplication-SIEMs normalize and deduplicate raw events to reduce noise and alert fatigue. EDR (B) is limited to endpoint telemetry; OSINT (C) is a data source, not a platform; UTM (D) is a network security appliance, not a SOC analytics and response platform.

Topics

#SIEM#SOC capabilities#threat intelligence#security analytics

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice