A large pharmaceutical company is undergoing a digital transformation, moving many on-premises applications to a multi-cloud environment. The cybersecurity architect needs to establish a unified threat intelligence and incident response strategy that spans both on-premises and cloud infrastructures to meet regulatory requirements for incident reporting. Which strategy is most effective?
- AImplementing separate SIEM and SOAR solutions for each cloud provider and for the on-premises environment.
- BDeploying a cloud-native SIEM/SOAR platform with extensive integration capabilities for both on-premises logs and multi-cloud environments, enabling centralized visibility and automated response.
- CRelying on individual cloud provider's native security services for incident response within their respective environments.
- DDeveloping a manual incident response plan that requires human correlation of alerts from disparate systems.
Show answer & explanationAnswer & explanation
Correct answer: B. Deploying a cloud-native SIEM/SOAR platform with extensive integration capabilities for both on-premises logs and multi-cloud environments, enabling centralized visibility and automated response.
A centralized SIEM/SOAR platform with extensive integration capabilities provides unified visibility across hybrid and multi-cloud environments, enabling correlation of threats, automated incident response, and streamlined reporting essential for regulatory compliance.
Why the other options are wrong
- A. Separate SIEM/SOAR solutions create silos, hindering unified threat intelligence, correlation across environments, and efficient incident response, leading to compliance gaps.
- C. Native cloud services are often siloed to their specific cloud and do not provide unified visibility or coordinated response across a multi-cloud or hybrid environment.
- D. Manual correlation of alerts is inefficient, prone to error, and impractical for the volume and complexity of threats in a large, hybrid environment, making timely incident reporting difficult.
Hybrid/Multi-Cloud SIEM/SOAR
A security operations platform designed to collect, analyze, and automate responses to security events across diverse environments, including on-premises, private cloud, and multiple public cloud providers.
- Provides unified visibility and threat correlation across disparate infrastructures.
- Enables consistent incident response workflows regardless of event source.
- Crucial for compliance in complex IT landscapes.
Memory trick: Centralized SIEM/SOAR Unifies Hybrid Cloud Defense