350-201 Question 130
Single answerYour organization uses a Security Information and Event Management (SIEM) tool to monitor and analyze security events. During an investigation of a potential insider threat, you notice that a user has been accessing sensitive information from multiple devices in different geographic locations within a short time frame. Which SIEM feature would be most useful in detecting this type of anomalous activity?
- A
Log aggregation and correlation
- B
User behavior analytics (UBA)
- C
Threat intelligence integration
- D
Automated incident response
Show answer and explanation
Correct answer: B
Explanation
SIEM tools use various features to enhance security data analytics. In this scenario, detecting anomalous user activity, such as accessing data from multiple locations in a short time frame, is best accomplished using User Behavior Analytics (UBA). UBA employs machine learning and statistical models to identify deviations from normal behavior, making it the most relevant feature for this use case.
- A. Incorrect.
Log aggregation and correlation collect and combine logs from different sources for analysis, but it does not inherently identify behavioral anomalies such as unusual user activity.
- B. Correct.
User behavior analytics (UBA) is specifically designed to detect anomalies in user actions, such as unusual access patterns or suspicious behaviors, making it highly relevant for detecting insider threats.
- C. Incorrect.
Threat intelligence integration helps identify external threats based on threat feeds and indicators of compromise (IOCs), but it does not focus on user behavior within the organization.
- D. Incorrect.
Automated incident response helps respond to detected threats, but it does not contribute to the detection of anomalous user activity itself.