nerdexam
(ISC)2

CSSLP · Question #19

You work as a Security Manager for Tech Perfect Inc. You have set up a SIEM server for the following purposes: Analyze the data from different log sources Correlate the events among the log entries Id

The correct answer is A. Asset information storage and correlation C. Incident tracking and reporting D. Security knowledge base E. Graphical user interface. Effective SIEM features for analyzing, correlating, identifying, and responding to security events include asset information storage and correlation, incident tracking and reporting, a security knowledge base, and a graphical user interface.

Secure Software Deployment, Operations, Maintenance

Question

You work as a Security Manager for Tech Perfect Inc. You have set up a SIEM server for the following purposes: Analyze the data from different log sources Correlate the events among the log entries Identify and prioritize significant events Initiate responses to events if required One of your log monitoring staff wants to know the features of SIEM product that will help them in these purposes. What features will you recommend? Each correct answer represents a complete solution. Choose all that apply.

Options

  • AAsset information storage and correlation
  • BTransmission confidentiality protection
  • CIncident tracking and reporting
  • DSecurity knowledge base
  • EGraphical user interface

How the community answered

(22 responses)
  • A
    86% (19)
  • B
    14% (3)

Why each option

Effective SIEM features for analyzing, correlating, identifying, and responding to security events include asset information storage and correlation, incident tracking and reporting, a security knowledge base, and a graphical user interface.

AAsset information storage and correlationCorrect

Asset information storage and correlation allows the SIEM to contextualize log data with details about critical assets, improving the accuracy of event prioritization and response.

BTransmission confidentiality protection

Transmission confidentiality protection is a security control for data in transit, ensuring logs are securely sent to the SIEM, but it is not a feature of the SIEM product itself that helps with analysis, correlation, identification, or response once the data is received.

CIncident tracking and reportingCorrect

Incident tracking and reporting features are essential for managing security incidents identified by the SIEM, enabling effective follow-up, documentation, and compliance.

DSecurity knowledge baseCorrect

A security knowledge base provides context and intelligence on known threats, vulnerabilities, and attack patterns, enhancing the SIEM's ability to identify and prioritize significant events.

EGraphical user interfaceCorrect

A graphical user interface (GUI) is crucial for log monitoring staff to efficiently visualize, navigate, and interact with the complex data and alerts generated by the SIEM, enabling quicker analysis and response.

Concept tested: SIEM product features and capabilities

Source: https://csrc.nist.gov/publications/detail/sp/800-92/final

Topics

#SIEM#Security Operations#Log Management#Incident Response

Community Discussion

No community discussion yet for this question.

Full CSSLP Practice