QuestionQ23

Managing a Security Operations Center

Which SIEM capability helps reduce false positives?

  • A Network extraction
  • B Event correlation
  • C Default alerting
  • D Input-driven logging
Explanation

SIEM event correlation analyzes related events together and applies contextual rules or patterns, which filters isolated or benign activity that might otherwise generate unnecessary alerts.

Community Discussion

No comments yet. Be the first to start the discussion!