CompTIA SecurityX (CAS-005)Security OperationsMedium

A company is implementing a new security monitoring solution. They want to ensure that all critical security events are captured and analyzed in real-time, but they are concerned about the volume of data and the potential for alert fatigue. Which of the following approaches best balances comprehensive monitoring with efficient alert management?

  1. ACollect all available logs from all systems and configure alerts for every logged event.
  2. BOnly collect logs from perimeter devices and rely on signature-based IDS for detection.
  3. CFocus on collecting logs from critical assets and apply correlation rules to generate alerts for high-fidelity security incidents.
  4. DImplement a 'set and forget' approach, using default SIEM rules and reviewing alerts weekly.
Show answer & explanation

Correct answer: C. Focus on collecting logs from critical assets and apply correlation rules to generate alerts for high-fidelity security incidents.

Collecting logs only from critical assets reduces data volume, while applying correlation rules helps to filter out noise and generate high-fidelity alerts for actual security incidents, effectively balancing comprehensive monitoring with efficient alert management.

Why the other options are wrong

  • A. Collecting all logs and alerting on every event would lead to massive data volume, severe alert fatigue, and make incident detection impossible.
  • B. Only monitoring perimeter devices creates blind spots for internal threats and lateral movement, compromising comprehensive security.
  • D. A 'set and forget' approach with default rules and weekly reviews is insufficient for real-time threat detection and response, leading to missed incidents.

SIEM Correlation Rules

Logic-based expressions within a Security Information and Event Management (SIEM) system that analyze multiple security events from different sources to identify patterns indicative of a threat or security incident.

  • Connects disparate events to form a complete picture.
  • Reduces false positives and alert fatigue.
  • Enhances detection of complex, multi-stage attacks.

Memory trick: Smart SIEMs don't just collect, they connect and prioritize.

More Security Operations questions