200-201 Question 14
Select 3A security operations center (SOC) team is overwhelmed by a large volume of alerts generated by multiple security tools. They also face delays in responding to incidents due to manual investigation and remediation steps. Which combination of solutions would best address these challenges?
- A
Implementing a SIEM solution to consolidate and analyze security logs
- B
Deploying a SOAR platform to automate response procedures
- C
Using only manual log management processes to track security events
- D
Eliminating redundant security tools to reduce the number of alerts
- E
Integrating SIEM and SOAR solutions for both alert correlation and automated response
Show answer and explanation
Correct answers: A, B, E
Explanation
The combination of SIEM and SOAR solutions is the most effective way to address the SOC team's challenges. A SIEM consolidates and analyzes logs to reduce alert fatigue, while a SOAR platform automates incident response and remediation. Together, they provide a comprehensive approach to managing high volumes of alerts and improving response times, which is critical for efficient security operations.
- A. Correct.
Implementing a SIEM solution helps aggregate and correlate logs from multiple sources, making it easier to identify patterns and reduce alert fatigue.
- B. Correct.
A SOAR platform can automate repetitive tasks such as incident triage, investigation, and response, significantly reducing the SOC team's workload.
- C. Incorrect.
Relying only on manual log management is inefficient and limits the team's ability to handle large-scale or complex incidents effectively.
- D. Incorrect.
While eliminating redundant tools may reduce some alerts, it does not address the need for better alert correlation or automated response capabilities.
- E. Correct.
Integrating SIEM and SOAR solutions combines the strengths of both tools, providing centralized log analysis and automation for faster and more effective incident response.