SIEM Flashcards

1
Q

What are the main SIEM capabilities?

A
  1. Data aggregation
  2. Correlation
  3. Alerting
  4. Dashboards
  5. Compliance
  6. Retention
  7. Forensics analysis
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Can you name three SIEM products?

A

HP’s ArcSight

Splunk

IBM’s Tivoli

Tools from LogLogic

Symantec’s security information manager

How well did you know this?
1
Not at all
2
3
4
5
Perfectly