Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 300-745 Exam - Topic 3 Question 9 Discussion

Which tool must be used to prioritize incidents by a SOC?
A) SIEM
B) endpoint detection and response
C) CloudWatch
D) endpoint protection platform

Cisco 300-745 Exam - Topic 3 Question 9 Discussion

Actual exam question for Cisco's 300-745 exam
Question #: 9
Topic #: 3
[All 300-745 Questions]

Which tool must be used to prioritize incidents by a SOC?

Show Suggested Answer Hide Answer
Suggested Answer: A

A Security Operations Center (SOC) is often overwhelmed by thousands of alerts from various security tools. The primary tool used to aggregate, correlate, and---most importantly---prioritize these incidents is the Security Information and Event Management (SIEM) system. According to the Cisco SDSI domain on Risk, Events, and Requirements, a SIEM acts as the central brain of the SOC.

A SIEM (such as Splunk or Cisco Secure Cloud Analytics) ingests logs from firewalls, endpoints, and cloud services. It uses correlation rules and risk-scoring algorithms to distinguish between low-priority 'noise' and critical security incidents. For example, a single failed login might be ignored, but ten failed logins followed by a successful one and a large data transfer would be escalated as a high-priority incident. Endpoint Detection and Response (EDR) (Option B) and Endpoint Protection Platforms (EPP) (Option D) provide deep visibility and protection on individual hosts but lack the cross-platform correlation needed to prioritize organizational risk. CloudWatch (Option C) is a monitoring service for AWS resources but does not function as a multi-source security correlation engine. By using a SIEM, SOC analysts can focus their limited time on the most impactful threats, ensuring a more efficient and effective incident response process.

========


Contribute your Thoughts:

0/2000 characters
Lashaunda
3 days ago
Yes, it integrates multiple data sources too.
upvoted 0 times
...
Jerlene
8 days ago
SIEM is definitely the best choice for SOC.
upvoted 0 times
...
Jarvis
13 days ago
D) endpoint protection platform is good, but not for prioritization.
upvoted 0 times
...
Leonor
19 days ago
C) CloudWatch is more for monitoring, not prioritizing.
upvoted 0 times
...
Laticia
24 days ago
True, but SIEM gives a broader view of incidents.
upvoted 0 times
...
Alayna
29 days ago
But what about B) endpoint detection and response? It targets specific threats.
upvoted 0 times
...
Lashaunda
1 month ago
I agree, SIEM provides real-time data.
upvoted 0 times
...
Jerlene
1 month ago
I think it's A) SIEM. It helps analyze incidents effectively.
upvoted 0 times
...
Lavina
1 month ago
I’m surprised this is even a question, it’s obviously A!
upvoted 0 times
...
Justa
2 months ago
A) SIEM is the standard, can't argue with that!
upvoted 0 times
...
Laquanda
2 months ago
Wait, isn't CloudWatch more for monitoring than prioritizing?
upvoted 0 times
...
Refugia
2 months ago
I think B) endpoint detection and response is better for that.
upvoted 0 times
...
Hayley
2 months ago
Definitely A) SIEM for prioritizing incidents.
upvoted 0 times
...
Victor
2 months ago
I feel like endpoint protection platforms might help, but I can't recall if they actually prioritize incidents like SIEM does.
upvoted 0 times
...
Cristal
4 months ago
CloudWatch seems more focused on monitoring AWS resources, so I doubt it's the right answer for prioritizing incidents.
upvoted 0 times
...
Adell
4 months ago
I remember practicing a question about incident prioritization, and I think it was related to endpoint detection and response tools.
upvoted 0 times
...
Raymon
4 months ago
I think the SIEM is the right choice since it aggregates logs and helps prioritize incidents, but I'm not entirely sure.
upvoted 0 times
...

Save Cancel