Which two processes are critical to a security information and event management (SIEM) platform? (Choose two.)
Detection of threats using data analysis -- SIEM platforms analyze collected data to identify suspicious patterns and detect threats.
Ingestion of log data -- SIEM systems collect and centralize log data from various sources, which is essential for analysis, correlation, and alerting.
Automation and prevention are more aligned with SOAR and firewall/EDR functionalities, not the core operations of SIEM.
Currently there are no comments in this discussion, be the first to comment!