QuestionQ73

Security Operations

A security analyst reviews a SIEM and produces the following report:

Question Image

Later, the incident response team determines that an attack was carried out on the VM001 host. What should the security analyst do to improve the SIEM platform's alerting process?

  • A Include the EDR solution on the SIEM as a new log source.
  • B Perform a log correlation on the SIEM solution.
  • C Improve parsing of data on the SIEM.
  • D Create a new rule set to detect malware.
Explanation

Accurate field parsing is required for a SIEM to normalize log events and apply alerting logic to fields such as hostname, event ID, action, and time. The malware-detection event is improperly parsed into a single destination-IP field, preventing reliable identification and alerting for VM001; improving the SIEM data parsing corrects this.

Community Discussion

No comments yet. Be the first to start the discussion!