Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 200-201 Exam - Topic 1 Question 82 Discussion

What is a difference between SI EM and SOAR security systems?
C) SIEM raises alerts in the event of detecting any suspicious activity, and SOAR automates investigation path workflows and reduces time spent on alerts
A) SOAR ingests numerous types of logs and event data infrastructure components and SIEM can fetch data from endpoint security software and external threat intelligence feeds
B) SOAR collects and stores security data at a central point and then converts it into actionable intelligence, and SIEM enables SOC teams to automate and orchestrate manual tasks
D) SIEM combines data collecting, standardization, case management, and analytics for a defense-in-depth concept, and SOAR collects security data antivirus logs, firewall logs, and hashes of downloaded files

Cisco 200-201 Exam - Topic 1 Question 82 Discussion

Actual exam question for Cisco's 200-201 exam
Question #: 82
Topic #: 1
[All 200-201 Questions]

What is a difference between SI EM and SOAR security systems?

Show Suggested Answer Hide Answer
Suggested Answer: C

Contribute your Thoughts:

0/2000 characters
Annamae
9 months ago
SIEM is crucial for data collection, can't overlook that!
upvoted 0 times
...
Helga
9 months ago
Wait, can SOAR really reduce alert response time?
upvoted 0 times
...
Glory
10 months ago
SOAR is all about automation, love it!
upvoted 0 times
...
Alaine
10 months ago
I thought SIEM did more than just alerting?
upvoted 0 times
...
Thaddeus
10 months ago
SOAR really helps streamline the process!
upvoted 0 times
...
Melina
10 months ago
I recall that SIEM does a lot of data aggregation and analysis, but SOAR is supposed to streamline the response process. I hope I can remember the details during the exam!
upvoted 0 times
...
Marti
11 months ago
I’m a bit confused about the specifics. I thought SIEM could also automate some tasks, but maybe that's more of a SOAR function?
upvoted 0 times
...
Willard
11 months ago
I practiced a question similar to this, and I feel like SOAR is more about integrating and acting on data, whereas SIEM is about collecting and analyzing it.
upvoted 0 times
...
Skye
11 months ago
I think I remember that SIEM is more about alerting and monitoring, while SOAR focuses on automating responses. But I'm not entirely sure how they differ in data handling.
upvoted 0 times
...
Carin
11 months ago
I'm feeling pretty confident about this one. SOAR is all about taking action on security alerts, while SIEM is more about detection and monitoring. I'll go with C.
upvoted 0 times
...
Jarvis
11 months ago
Okay, I've got this. SOAR is more about automating security workflows and incident response, while SIEM is focused on collecting and analyzing security data. The answer is probably B.
upvoted 0 times
...
Lino
11 months ago
Hmm, I'm a bit confused on the differences here. I'll need to review my notes on SIEM and SOAR capabilities to make sure I understand the distinction.
upvoted 0 times
...
Lamar
11 months ago
This question seems pretty straightforward. I think the key is to focus on the differences between SIEM and SOAR systems.
upvoted 0 times
...
Georgene
11 months ago
Building permit records seem like the most logical choice here. That's where I'd start to uncover the ownership details.
upvoted 0 times
...
Graciela
11 months ago
This is a good test of my understanding of these security technologies. I'll need to think critically about the relationships between them to determine the correct answer.
upvoted 0 times
...
Luisa
11 months ago
I'm leaning towards the idea that routing information is exchanged between the customer router and PEs, but it's such a nuanced topic.
upvoted 0 times
...
Eun
11 months ago
I think we discussed how AppFlow has to be enabled on each instance for monitoring to work. That seems like a likely issue here.
upvoted 0 times
...
Mose
11 months ago
I'm pretty sure this is asking about the FIPS 199 formula for categorizing information systems. I think the answer is C, since that matches the description of the formula having confidentiality, integrity, and availability each paired with "impact".
upvoted 0 times
...
Mignon
11 months ago
The question is pretty clear, and I believe Cisco Unified CCX Standard is the way to go. It seems to have the necessary features at a lower cost than the other options.
upvoted 0 times
...
My
2 years ago
And SIEM combines data collecting, standardization, case management, and analytics for a defense-in-depth concept.
upvoted 0 times
...
Macy
2 years ago
That's true, Roslyn. SOAR automates investigation path workflows and reduces time spent on alerts.
upvoted 0 times
...
Roslyn
2 years ago
But I believe SIEM raises alerts in case of detecting suspicious activity.
upvoted 0 times
...
My
2 years ago
I agree with Macy, SOAR collects and stores security data at a central point and converts it into actionable intelligence.
upvoted 0 times
...
Macy
2 years ago
I think the main difference is that SOAR ingests various types of logs and event data infrastructure components.
upvoted 0 times
...
Cecil
2 years ago
Definitely, it's important for security teams to understand the differences and choose the right tool for their requirements.
upvoted 0 times
...
Delpha
2 years ago
I think both have their own strengths and can be useful depending on the specific needs of the organization.
upvoted 0 times
...
Izetta
2 years ago
That's true, SIEM is more focused on alerting while SOAR is more about automation and reducing time spent on alerts.
upvoted 0 times
...
Oren
2 years ago
On the other hand, SIEM raises alerts in case of any suspicious activity, while SOAR automates investigation path workflows.
upvoted 0 times
...
Carissa
2 years ago
I agree with that, SOAR certainly has a wider range of data it can handle.
upvoted 0 times
...
Lezlie
2 years ago
I think the main difference is that SOAR ingests numerous types of logs and event data infrastructure components, while SIEM can fetch data from endpoint security software and external threat intelligence feeds.
upvoted 0 times
...
Rodrigo
2 years ago
Exactly! I was leaning towards B as well. Plus, option C just sounds wrong - SIEM systems are the ones that raise alerts, not SOAR.
upvoted 0 times
...
Arletta
2 years ago
That makes sense to me. SOAR is about the collection and analysis, while SIEM is about the automation and response. We need both in a comprehensive security strategy.
upvoted 0 times
...
Lawrence
2 years ago
Haha, yeah, that one was a bit of a head-scratcher. I can just picture a SOAR system being like, 'Nah, I'm not going to alert you to that suspicious activity. I'll just handle it myself!'
upvoted 0 times
Chan
2 years ago
Haha, yeah, that one was a bit of a head-scratcher. I can just picture a SOAR system being like, 'Nah, I'm not going to alert you to that suspicious activity. I'll just handle it myself!'
upvoted 0 times
...
Mariko
2 years ago
A) SOAR ingests numerous types of logs and event data infrastructure components and SIEM can fetch data from endpoint security software and external threat intelligence feeds
upvoted 0 times
...
Felix
2 years ago
C) SIEM raises alerts in the event of detecting any suspicious activity, and SOAR automates investigation path workflows and reduces time spent on alerts
upvoted 0 times
...
Gracia
2 years ago
A) SOAR ingests numerous types of logs and event data infrastructure components and SIEM can fetch data from endpoint security software and external threat intelligence feeds
upvoted 0 times
...
...

Save Cancel