Cisco CCNP Security Core (SCOR) 350-701Security ConceptsMedium
A security team is implementing a new SIEM solution. They want to ensure that the SIEM can effectively correlate events and detect advanced threats. To achieve this, they need to integrate threat intelligence feeds from various sources, including government agencies and private security vendors. This integration directly enhances which aspect of security operations?
- AIncident Response
- BSecurity Monitoring and Analysis
- CVulnerability Management
- DIdentity and Access Management
Show answer & explanationAnswer & explanation
Correct answer: B. Security Monitoring and Analysis
Integrating threat intelligence into a SIEM solution directly enhances security monitoring and analysis capabilities. It allows the SIEM to correlate incoming logs and events with known indicators of compromise (IOCs) and attack patterns, thereby improving threat detection.
Why the other options are wrong
- A. Incident response is the reaction to detected incidents; threat intelligence enhances the detection phase, which precedes or informs response.
- C. Vulnerability management focuses on identifying and remediating system weaknesses, not directly on real-time threat detection via SIEM.
- D. Identity and access management (IAM) controls who can access resources, unrelated to SIEM and threat intelligence correlation.
Security Monitoring & Analysis
The continuous process of collecting, reviewing, and analyzing security-related data from various sources to detect and respond to threats.
- Often relies on SIEM systems.
- Utilizes logs, alerts, and threat intelligence.
- Aims for early detection of security incidents.
Memory trick: Ops are the 'DO'ers, 'OPERATING' the security 'CONTROLS'.