CSSLP · Question #19
You work as a Security Manager for Tech Perfect Inc. You have set up a SIEM server for the following purposes: Analyze the data from different log sources Correlate the events among the log entries Id
The correct answer is A. Asset information storage and correlation C. Incident tracking and reporting D. Security knowledge base E. Graphical user interface. Effective SIEM features for analyzing, correlating, identifying, and responding to security events include asset information storage and correlation, incident tracking and reporting, a security knowledge base, and a graphical user interface.
Question
You work as a Security Manager for Tech Perfect Inc. You have set up a SIEM server for the following purposes: Analyze the data from different log sources Correlate the events among the log entries Identify and prioritize significant events Initiate responses to events if required One of your log monitoring staff wants to know the features of SIEM product that will help them in these purposes. What features will you recommend? Each correct answer represents a complete solution. Choose all that apply.
Options
- AAsset information storage and correlation
- BTransmission confidentiality protection
- CIncident tracking and reporting
- DSecurity knowledge base
- EGraphical user interface
How the community answered
(22 responses)- A86% (19)
- B14% (3)
Why each option
Effective SIEM features for analyzing, correlating, identifying, and responding to security events include asset information storage and correlation, incident tracking and reporting, a security knowledge base, and a graphical user interface.
Asset information storage and correlation allows the SIEM to contextualize log data with details about critical assets, improving the accuracy of event prioritization and response.
Transmission confidentiality protection is a security control for data in transit, ensuring logs are securely sent to the SIEM, but it is not a feature of the SIEM product itself that helps with analysis, correlation, identification, or response once the data is received.
Incident tracking and reporting features are essential for managing security incidents identified by the SIEM, enabling effective follow-up, documentation, and compliance.
A security knowledge base provides context and intelligence on known threats, vulnerabilities, and attack patterns, enhancing the SIEM's ability to identify and prioritize significant events.
A graphical user interface (GUI) is crucial for log monitoring staff to efficiently visualize, navigate, and interact with the complex data and alerts generated by the SIEM, enabling quicker analysis and response.
Concept tested: SIEM product features and capabilities
Source: https://csrc.nist.gov/publications/detail/sp/800-92/final
Topics
Community Discussion
No community discussion yet for this question.