QuestionQ22

Security Operations Center (SOC) Fundamentals

For which two use cases is using a SIEM more appropriate than using a SOAR solution to investigate a user who signs in from a malicious IP address?

Choose two
  • A Using predefined rules and patterns to identify data points
  • B Enriching data and triaging alert information
  • C Continuously monitoring data for pattern recognition
  • D Mapping external threats to SOC incidents
Explanation

A SIEM continuously collects and analyzes security event data, using analytics rules and correlations to detect defined indicators and suspicious behavioral patterns. SOAR is principally used to automate recurring enrichment, triage, response, and remediation workflows.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!