350-201 Question 128
Select 3An organization is deploying a new Security Information and Event Management (SIEM) solution to enhance their security data management capabilities. They want to ensure the SIEM can handle large volumes of data, provide actionable insights, and support compliance reporting. Which features should they prioritize in their SIEM deployment?
- A
Real-time data ingestion and correlation
- B
Integration with cloud and on-premises data sources
- C
Automated incident response capabilities
- D
Support for encryption and secure data storage
- E
Manual log analysis workflows to reduce automation complexity
Show answer and explanation
Correct answers: A, B, D
Explanation
The core functions of a SIEM solution in security data management include real-time data ingestion, integration with diverse data sources, and secure storage of sensitive information. These features allow organizations to detect threats, maintain compliance, and ensure the integrity of their data. While automation and efficiency are important, manual workflows are counterproductive in modern security environments.
- A. Correct.
Real-time data ingestion and correlation are critical for detecting and responding to threats quickly, making it a necessary feature for effective security data management.
- B. Correct.
Integration with cloud and on-premises data sources ensures the SIEM can aggregate and analyze data from diverse environments, which is essential for comprehensive visibility.
- C. Incorrect.
Automated incident response capabilities are valuable but are not directly tied to the core functions of security data management, such as ingestion, storage, and correlation.
- D. Correct.
Support for encryption and secure data storage is essential to protect sensitive security data and ensure compliance with regulations.
- E. Incorrect.
Manual log analysis workflows are not desirable in modern SIEM solutions as they reduce efficiency and scalability, which are essential for managing large volumes of security data.