Q: 16
The Chief Information Security Officer for an organization recently received approval to install a new
EDR solution. Following the installation, the number of alerts that require remediation by an analyst
has tripled. Which of the following should the organization utilize to best centralize the workload for
the internal security team? (Select two).
Options
Discussion
Had something like this in a mock. SOAR (A) and SIEM (B) are the best picks because SIEM pulls all alert data into one view and SOAR handles the automation to cut down manual work. XDR is more about detection across sources, not really centralizing workload for analysts.
Makes sense to me, going with A and B. SOAR centralizes and automates response, SIEM collects and correlates the alerts. Not totally sure but don't see how NGFW or MSP would help here.
Seen this in some practice tests and the official objectives. A (SOAR) and B (SIEM) are usually paired for alert centralization since SIEM collects the data, SOAR automates responses. Pretty sure that's what they're looking for here.
This kind of scenario pops up often in practice sets and guides. SIEM and SOAR together really help centralize alerts and automate responses. If the question said "most secure" instead of "centralize," would XDR (E) make more sense?
Be respectful. No spam.