Questions

  1. What elements would you typically expect to make up a SIEM environment?
    1. Client, server, agent
    2. Archive, cloud processor, contribution network
    3. Central processing node, sensors, database/logging
    4. Agents, sensors, logging, reporting, Central processing node
  1. How can SIEM directly support enhanced security services?
    1. By increasing the integrity of event messages
    2. By overlaying additional contextual information using authentication messages. This will achieve a correlated view of authentication
    3. By improving the overall availability of a processing environment
    4. By increasing the confidentiality of event messages
  1. When considering the budget of a SIEM service, what are the components that should be considered?
    1. Monitoring agents and ...

Get Practical Network Scanning now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.