13. Quizzes: SIEM

Which of the following would provide a more manageable amount of results while searching in a SIEM?

SOLUTION: 4-Hour Search for google.com sourcetype=dnssyslog

What are features of an Open Source SIEM?
[Select all that apply]

SOLUTION:
  • Customizable
  • Strong Community Support
  • Lack of restrictions on data ingestion

What are some considerations when choosing a SIEM?
[Select all that apply]

SOLUTION:
  • Licensing
  • Scalability
  • Dashboards
  • Alerts
  • Query Language