How does a security information and event management system (SIEM) in a SOC help the personnel fight against security threats?
- by analyzing logging data in real time
- by dynamically implementing firewall rules
- by combining data from multiple technologies
- by integrating all security devices and appliances in an organization
Answers Explanation & Hints:
A security information and event management system (SIEM) combines data from multiple sources to help SOC personnel collect and filter data, detect and classify threats, analyze and investigate threats, and manage resources to implement preventive measures. |