ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 597 - SY0-601 discussion

Report
Export

An organization is having difficulty correlating events from its individual AV. EDR. DLP. SWG. WAF, MDM. HIPS, and CASB systems. Which of the following is the best way to improve the situation?

A.
Remove expensive systems that generate few alerts.
Answers
A.
Remove expensive systems that generate few alerts.
B.
Modify the systems to alert only on critical issues.
Answers
B.
Modify the systems to alert only on critical issues.
C.
Utilize a SIEM to centralize logs and dashboards.
Answers
C.
Utilize a SIEM to centralize logs and dashboards.
D.
Implement a new syslog/NetFlow appliance.
Answers
D.
Implement a new syslog/NetFlow appliance.
Suggested answer: C

Explanation:

A SIEM (Security Information and Event Management) is a system that collects, analyzes, and correlates data from multiple sources, such as AV (antivirus), EDR (endpoint detection and response), DLP (data loss prevention), SWG (secure web gateway), WAF (web application firewall), MDM (mobile device management), HIPS (host intrusion prevention system), and CASB (cloud access security broker). A SIEM can help improve the situation by providing a centralized view of the security posture, alerts, and incidents across the organization.

asked 02/10/2024
Santanu Roy
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first