QuestionQ9
Log ManagementA large financial institution receives thousands of security logs each day from firewalls, IDS systems, and user-authentication platforms. The SOC team uses an AI-driven SIEM system with NLP capabilities to streamline threat detection. This approach enables quicker response times, reduces manual rule creation, and helps identify advanced threats that traditional systems might miss. Which of the following BEST demonstrates the advantage of NLP in SIEM?
- A Enables analysis of text-based data from logs and communications to detect threats
- B Eliminates the need for data normalization and correlation in SIEM systems
- C Allows security analysts to write SIEM rules using complex programming languages
- D Simplifies infrastructure management by reducing hardware dependencies
Community Discussion