QuestionQ22
Security Operations Center (SOC) FundamentalsFor which two use cases is using a SIEM more appropriate than using a SOAR solution to investigate a user who signs in from a malicious IP address?
Choose two
- A Using predefined rules and patterns to identify data points
- B Enriching data and triaging alert information
- C Continuously monitoring data for pattern recognition
- D Mapping external threats to SOC incidents
Community Discussion