The Chief Information Security Officer for an organization recently received approval to install a new EDR solution. Following the installation, the number of alerts that require remediation by an analyst has tripled. Which of the following should the organization utilize to best centralize the workload for the internal security team? (Select two).
SOAR (Security Orchestration, Automation and Response) and SIEM (Security Information and Event Management) are solutions that can help centralize the workload for the internal security team by collecting, correlating, and analyzing alerts from different sources, such as EDR. SOAR can also automate and streamline incident response workflows, while SIEM can provide dashboards and reports for security monitoring and compliance. Reference: What is EDR? Endpoint Detection & Response, How Does the Cyber Kill Chain Protect Against Attacks?; What is EDR Solution?, EDR solutions secure diverse endpoints through central monitoring
An
10 months agoKati
10 months agoRoyal
10 months agoMilly
10 months agoAleisha
11 months agoMalinda
11 months agoMargot
11 months agoElina
11 months agoKirk
11 months agoIsabelle
11 months agoTrevor
11 months agoSuzan
11 months agoTresa
11 months agoIdella
11 months agoKarrie
12 months agoCassi
12 months agoMiriam
12 months agoGlory
12 months agoJamie
12 months agoMagdalene
2 years agoPercy
2 years agoCyndy
2 years agoMignon
2 years agoDannette
2 years agoLonna
2 years agoTiera
2 years agoFlorinda
2 years agoHollis
2 years agoLuisa
2 years agoEdelmira
2 years agoTracey
2 years ago