QuestionQ16

Security Operations

A security consultant recommends deploying a solution to increase awareness of APTs across the IT and ОТ environments. The consultant requires that the solution must:

  • Be able to collect data from both ОТ and IT protocols.
  • Function within the new microsegmented and air-gapped network architecture.
  • Provide both event correlation and retention of raw log data and incidents.
  • Integrate with the ITSM platform and employee paging system.

Which of the following solutions best fulfills these requirements?

Explanation

A SIEM uses distributed or remote collectors to ingest logs from IT and OT systems across segmented network zones, centralizes raw-log retention, correlates events into incidents, and supports integrations with IT service-management and paging workflows. Microsoft Sentinel documentation describes collectors/forwarders for device logs, correlation of security data, and configurable log retention.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!