Security Operations第 65 / 100 题
Which system aggregates and correlates log data from many sources to detect security events in near real time?
a.IDS
b.DLP
c.SIEM
d.VPN
解析
A security information and event management (SIEM) system centralizes logs from across the environment and correlates them to surface incidents. It supports alerting, dashboards, and investigation. Effective tuning reduces alert fatigue and false positives.
免费刷完整 100 道题库 — 无需注册。
同考点相关题目
- Which is the correct order of the incident response process?
- During incident response, which step focuses on limiting the damage and preventing the threat from spreading?
- Which control monitors network traffic and actively blocks detected malicious activity inline?
- Which technology inspects data in motion and at rest to prevent unauthorized exfiltration of sensitive information?
- Which process applies vendor updates to fix known software vulnerabilities?
- Reducing a system's attack surface by disabling unneeded services and applying secure configurations is called: