QuestionQ127

Security Operations and Management

Robin, a SOC engineer at a multinational company, is planning to implement a SIEM. He determined that his organization can perform only the Correlation, Analytics, Reporting, Retention, Alerting, and Visualization functions required for the SIEM implementation, and must obtain collection and aggregation services from a Managed Security Services Provider (MSSP). What type of SIEM is Robin planning to implement?

  • A Hybrid Model, Jointly Managed
  • B Cloud, Self-Managed
  • C Self-hosted, Self-Managed
  • D Self-hosted, MSSP Managed
Explanation

A cloud, self-managed SIEM model assigns event collection and aggregation to the MSSP while the organization performs correlation, analytics, alerting, visualization, reporting, and retention. This preserves internal ownership of SIEM analysis and operations while outsourcing log-ingestion services.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!