Certified Information Security Manager (CISM)Information Security Risk ManagementHard

A large multinational corporation uses a complex array of security tools, generating millions of logs daily. The security operations center (SOC) analysts are overwhelmed by the volume of alerts, leading to potential missed incidents. The CISO wants to improve the efficiency and effectiveness of threat detection and response. Which of the following solutions would provide the MOST immediate and impactful improvement?

  1. AIncrease the number of SOC analysts and provide more comprehensive training.
  2. BDeploy an advanced Endpoint Detection and Response (EDR) solution across all endpoints.
  3. CImplement Security Orchestration, Automation, and Response (SOAR) capabilities.
  4. DMigrate all security logs to a cloud-based Security Information and Event Management (SIEM) system.
Show answer & explanation

Correct answer: C. Implement Security Orchestration, Automation, and Response (SOAR) capabilities.

SOAR platforms are designed to integrate security tools, automate incident response workflows, and orchestrate complex tasks, directly addressing the overwhelming volume of alerts and improving the efficiency and effectiveness of threat detection and response in an immediate and impactful way.

Why the other options are wrong

  • A. Increasing analysts and training is important but doesn't solve the fundamental problem of overwhelming alert volume; it's a scaling issue that automation can better address.
  • B. EDR enhances endpoint visibility and response but doesn't directly address the alert fatigue from multiple tools or orchestrate overall response.
  • D. Migrating to a cloud SIEM might offer scalability and performance, but it doesn't inherently solve the problem of alert overload or automate response workflows without additional capabilities like SOAR.

Security Orchestration, Automation, and Response (SOAR)

A cybersecurity solution that helps organizations collect threat-related data, orchestrate security operations, and automate responses to security incidents, reducing manual effort and improving reaction times.

  • Integrates security tools and workflows.
  • Automates repetitive incident response tasks.
  • Enhances efficiency and effectiveness of SOC operations.

Memory trick: SOAR over the alert storm.

More Information Security Risk Management questions