ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 280 - CS0-003 discussion

Report
Export

The Chief Information Security Officer for an organization recently received approval to install a new EDR solution. Following the installation, the number of alerts that require remediation by an analyst has tripled. Which of the following should the organization utilize to best centralize the workload for the internal security team? (Select two).

A.
SOAR
Answers
A.
SOAR
B.
SIEM
Answers
B.
SIEM
C.
MSP
Answers
C.
MSP
D.
NGFW
Answers
D.
NGFW
E.
XDR
Answers
E.
XDR
F.
DLP
Answers
F.
DLP
Suggested answer: A, B

Explanation:

SOAR (Security Orchestration, Automation and Response) and SIEM (Security Information and Event Management) are solutions that can help centralize the workload for the internal security team by collecting, correlating, and analyzing alerts from different sources, such as EDR. SOAR can also automate and streamline incident response workflows, while SIEM can provide dashboards and reports for security monitoring and compliance.

Reference: What is EDR? Endpoint Detection & Response, How Does the Cyber Kill Chain Protect Against Attacks?; What is EDR Solution?, EDR solutions secure diverse endpoints through central monitoring



asked 02/10/2024
Crystal Eagle
31 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first