QuestionQ312

Tools/Systems/Programs

During a post-incident investigation at an energy company, analysts are tasked with identifying coordinated malicious activity by examining security data generated from multiple control points, including network defenses and server systems. The investigation requires a platform that can ingest diverse event sources, relate activity across those sources as it occurs, and surface actionable findings to support analyst-led investigation through a unified interface.

How should analysts enable this type of real-time, cross-source event analysis and investigation?

  • A ManageEngine EventLog Analyzer
  • B ELK Stack (Elasticsearch, Logstash, Kibana)
  • C OSSEC HIDS
  • D IBM QRadar
Explanation

IBM QRadar is a Security Information and Event Management (SIEM) platform designed to collect and normalize events from many heterogeneous sources — including network security devices and servers — correlate that activity in real time to detect coordinated attack patterns, and present prioritized findings through a unified console for analyst-driven investigation, distinguishing it from single-purpose log analyzers, do-it-yourself log stacks, and host-based intrusion detection tools.

Community Discussion

No comments yet. Be the first to start the discussion!