組織のネットワーク スペシャリストである Camden は、制御室から SIFM を使用して組織のネットワークの動作を監視しました。SIEM は疑わしいアクティビティを検出し、カメラ a にアラートを送信しました。画面に表示されたインシデントの重大度に基づいて、Camden は正しい判断を下し、攻撃者によるさらなる悪用を防ぐためにすぐに防御措置を開始しました。
次の SIEM 機能のうち、Camden がセキュリティ インシデント発生時に疑わしい動作を確認し、正しい判断を下すのに役立ったものはどれですか。
正解:C
Dashboard is the SIEM function that allowed Camden to view suspicious behavior and make correct decisions during a security incident. SIEM (Security Information and Event Management) is a system or software that collects, analyzes, and correlates security data from various sources, such as logs, alerts, events, etc., and provides a centralized view and management of the security posture of a network or system. SIEM can be used to detect, prevent, or respond to security incidents or threats. SIEM consists of various functions or components that perform different tasks or roles. Dashboard is a SIEM function that provides a graphical user interface (GUI) that displays various security metrics, indicators, alerts, reports, etc., in an organized and interactive manner. Dashboard can be used to view suspicious behavior and make correct decisions during a security incident. In the scenario, Camden monitored the behavior of the organizational network using SIEM from a control room. The SIEM detected suspicious activity and sent an alert to Camden. Based on the severity of the incident displayed on the screen, Camden made the correct decision and immediately launched defensive actions to prevent further exploitation by attackers. This means that he used the dashboard function of SIEM for this purpose. Application log monitoring is a SIEM function that collects and analyzes application logs, which are records of events or activities that occur within an application or software. Log retention is an SIEM function that stores and preserves logs for a certain period of time or indefinitely for future reference or analysis. Data aggregation is an SIEM function that combines and normalizes data from different sources into a common format or structure.