Security Information and Event Management (SIEM) Flashcards

1
Q

What is a SIEM?

A

Security Information Event Management

solution that provides real-time or near real-time analysis of your security alerts that are being generated by network hardware and applications.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is an Agent?

A

small piece of software that’s going to be installed on each system, such as a server or workstation from which the SIEM needs to gather and collect log data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is Agentless Installation?

A

Under this approach, the SIEM system will directly collect log data from each system using a standard protocol like SNMP or WMI.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is Splunk?

A

market-leading big data information-gathering and analysis tool that can import machine-generated data via a connector or a visibility add-on.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What ELK (Elastic Stack)?

A

collection of free and open source SIEM tools that provide storage, search, and analysis functions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is ArcSight?

A

SIEM log management and analytics software that can be used for compliance reporting for legislation and regulations like HIPAA, SOX and PCI DSS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is QRadar?

A

SIEM log management analytics and compliance reporting platform, but this one was created by IBM.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly