CompTIA SecurityX (CAS-005)Security OperationsMedium
A company is implementing a new security monitoring solution. They want to ensure that all critical security events are captured and analyzed in real-time, but they are concerned about the volume of data and the potential for alert fatigue. Which of the following approaches best balances comprehensive monitoring with efficient alert management?
- ACollect all available logs from all systems and configure alerts for every logged event.
- BOnly collect logs from perimeter devices and rely on signature-based IDS for detection.
- CFocus on collecting logs from critical assets and apply correlation rules to generate alerts for high-fidelity security incidents.
- DImplement a 'set and forget' approach, using default SIEM rules and reviewing alerts weekly.
Show answer & explanationAnswer & explanation
Correct answer: C. Focus on collecting logs from critical assets and apply correlation rules to generate alerts for high-fidelity security incidents.
Collecting logs only from critical assets reduces data volume, while applying correlation rules helps to filter out noise and generate high-fidelity alerts for actual security incidents, effectively balancing comprehensive monitoring with efficient alert management.
Why the other options are wrong
- A. Collecting all logs and alerting on every event would lead to massive data volume, severe alert fatigue, and make incident detection impossible.
- B. Only monitoring perimeter devices creates blind spots for internal threats and lateral movement, compromising comprehensive security.
- D. A 'set and forget' approach with default rules and weekly reviews is insufficient for real-time threat detection and response, leading to missed incidents.
SIEM Correlation Rules
Logic-based expressions within a Security Information and Event Management (SIEM) system that analyze multiple security events from different sources to identify patterns indicative of a threat or security incident.
- Connects disparate events to form a complete picture.
- Reduces false positives and alert fatigue.
- Enhances detection of complex, multi-stage attacks.
Memory trick: Smart SIEMs don't just collect, they connect and prioritize.