Which of the following should the SIEM support?

A security technician is incorporating the following requirements in an RFP for a new SIEM:
New security notifications must be dynamically implemented by the SIEM engine
The SIEM must be able to identify traffic baseline anomalies
Anonymous attack data from all customers must augment attack detection and risk scoring
Based on the above requirements, which of the following should the SIEM support? (Choose two.)
A. Autoscaling search capability
B. Machine learning
C. Multisensor deployment
D. Big Data analytics
E. Cloud-based management
F. Centralized log aggregation

How to PASS CAS-004 in First Attempt?

FULL Printable PDF and Software. VALID exam to help you PASS.

comptia-exams

6 thoughts on “Which of the following should the SIEM support?

  1. Lookiing at centralized log aggregation–that is almost the definition of a SIEM. Here we want a SIEM which is dynamic so machine learning is a given. Now, I have to choose between Big Data Analytics and cloud based management. Cloud based would create an easier pull to collect information and adapt quickly to new vulnerabilities or attack. However, it says cloud management–which I am less comfortable will do that.
    So I will go with B & D.

  2. I like B, and F

    Machine learning = The SIEM must be able to identify traffic baseline anomalies

    Centralized log aggregation = Anonymous attack data from all customers must augment attack detection and risk scoring

    2
    2
  3. “The SIEM must be able to identify traffic baseline anomalies” Integrating machine learning would do that. B-

    “New security notifications must be dynamically implemented by the SIEM engine” sounds like cloud-based managment. E-

    Auto scaling search and Centralized log aggregation are great and adding Big data analytics would definitely give your SIEM capabilities a boost, but for me, when analyzing what the question is asking, I have to go with B and E.

    1
    2
    1. “when analyzing what the question is asking, I have to go with B and E.”

      You didn’t analyze the question..

      A siem already has centralized log aggregation.

      3
      2

Leave a Reply

Your email address will not be published. Required fields are marked *


The reCAPTCHA verification period has expired. Please reload the page.