Loading...
Master key concepts with interactive flashcards
What is the primary purpose of a SIEM in a SOC?
Click to reveal answer
A SIEM (Security Information and Event Management) system aggregates log data from across the environment, correlates events against detection rules, and generates prioritized alerts for analyst investigation. It provides centralized visibility, threat hunting capability, and forensic investigation support.
Click to show question