ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 38 - CS0-003 discussion

Report
Export

Which of the following is the best metric for an organization to focus on given recent investments in SIEM, SOAR, and a ticketing system?

A.
Mean time to detect
Answers
A.
Mean time to detect
B.
Number of exploits by tactic
Answers
B.
Number of exploits by tactic
C.
Alert volume
Answers
C.
Alert volume
D.
Quantity of intrusion attempts
Answers
D.
Quantity of intrusion attempts
Suggested answer: A

Explanation:

Mean time to detect (MTTD) is the best metric for an organization to focus on given recent investments in SIEM, SOAR, and a ticketing system. MTTD is a metric that measures how long it takes to detect a security incident or threat from the time it occurs. MTTD can be improved by using tools and processes that can collect, correlate, analyze, and alert on security data from various sources. SIEM, SOAR, and ticketing systems are examples of such tools and processes that can help reduce MTTD and enhance security operations. Official

Reference: https://www.eccouncil.org/cybersecurity-exchange/threat-intelligence/cyber-kill-chain-seven-steps-cyberattack

asked 02/10/2024
Eduardo Messias Andrade e Oliveira
35 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first