A security analyst in a SOC has been tasked with onboarding a new network into the SIEM. Which of the following BEST describes the information that should feed into a SIEM solution in order to adequately support an investigation?
Corrects Answer A. Logs from each device type and security layer to provide correlation of events
The best approach for feeding data into a SIEM (Security Information and Event Management) solution is to gather logs from each device type and security layer within the network. This comprehensive set of logs allows for the correlation of events across various devices (e.g., firewalls, routers, switches, servers, endpoints, and security appliances) and provides a complete picture of network activities. By collecting logs from different sources, the SIEM can more effectively detect, analyze, and respond to security incidents, as it has broader context and visibility across the entire network environment.
Reasons the other options are incorrect:
No Payment Cards Needed
Discover a range of courses designed to provide you with the knowledge and skills needed to excel in your chosen field.
You don’t need one month to study and pass your test.
With Prepsaret, it takes you a few days to grasp all the concepts needed to pass your exams