CRISC · Question #484
Which of the following is BEST used to aggregate data from multiple systems to identify abnormal behavior?
The correct answer is D. SIEM systems. SIEM (Security Information and Event Management) systems are designed to aggregate and analyze security data from various sources to detect anomalous behavior.
Question
Which of the following is BEST used to aggregate data from multiple systems to identify abnormal behavior?
Options
- ACyber threat intelligence
- BAnti-malware software
- CEndpoint detection and response (EDR)
- DSIEM systems
How the community answered
(40 responses)- A3% (1)
- C5% (2)
- D93% (37)
Why each option
SIEM (Security Information and Event Management) systems are designed to aggregate and analyze security data from various sources to detect anomalous behavior.
Cyber threat intelligence provides context about threats but does not aggregate operational data from internal systems for real-time anomaly detection.
Anti-malware software primarily detects and removes malicious software on individual endpoints, not aggregates data from multiple systems for behavioral analysis.
Endpoint Detection and Response (EDR) focuses on monitoring and responding to threats at the endpoint level, offering deeper visibility into individual systems but not the broad aggregation and correlation across multiple diverse systems as SIEM does.
SIEM (Security Information and Event Management) systems are specifically engineered to collect, aggregate, normalize, and analyze log data and events from diverse sources across an IT environment. This centralized analysis capability allows SIEMs to correlate seemingly unrelated events to identify patterns indicative of abnormal or malicious behavior that individual systems might miss.
Concept tested: SIEM functionality for anomaly detection
Source: https://learn.microsoft.com/en-us/azure/sentinel/overview
Topics
Community Discussion
No community discussion yet for this question.