Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Security OperationsHard
A SOC analyst is using a Security Information and Event Management (SIEM) system to investigate a series of alerts. The analyst notices that several low-severity events, such as failed login attempts and access to unusual file types, are occurring from the same internal host. Individually, these events are not critical, but when viewed together, they suggest malicious activity. What SIEM capability is most crucial for detecting this type of complex attack pattern?
- AReporting and Dashboards
- BData Normalization
- CLog Aggregation
- DEvent Correlation
Show answer & explanationAnswer & explanation
Correct answer: D. Event Correlation
Event correlation is the SIEM's ability to analyze multiple disparate security events from different sources (or even the same source over time) and identify relationships or patterns that indicate a more significant threat. In this scenario, individually low-severity events become critical when correlated to reveal a complex attack pattern.
Why the other options are wrong
- A. Reporting and dashboards visualize data, but don't perform the underlying analysis to detect the pattern.
- B. Data normalization standardizes log formats, which aids correlation but isn't the correlation itself.
- C. Log aggregation collects logs, but doesn't inherently link events to find patterns.
SIEM Event Correlation
SIEM Event Correlation is the process of analyzing multiple security events from various sources to identify relationships, patterns, and sequences that indicate a potential security threat or incident, especially those that individual events might not reveal.
- Links disparate events.
- Identifies complex attack patterns.
- Reduces false positives by increasing context.
Memory trick: Collect, Normalize, Correlate, Alert, Report.