SIEM and SOAR systems Flashcards

1
Q

What does SIEM stand for

A

SEcurity information and event management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What does SIEM do?

A

It gathers a immense amount of data, with the ability to do firewalls, IDS, IPS solutions. Then you can log, aggregate, normalized, and review. The main components are security Infomation management and Security Event management.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the SIM (security Information Management?

A

Collects and stores then aggregates log data for your review

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is a SEM (Security Event Managemet)

A

collects any threats or events that are occuring, then aggregate and then normalize for your review

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is security orchestration automation response?

A

It is a very manual response that provides an automated response, with a streamiline the response process while used in conjuction with a SIEM

How well did you know this?
1
Not at all
2
3
4
5
Perfectly