Q8Security Concepts
What distinguishes SOAR from SIEM?
← → navigate · a answer
Community votes
Discussion · 15
16
Platforms built on SIEM (security information and event management) technology provide visibility and useful insights by gathering, consolidating, and analyzing data from different sources.
A newer platform in the security industry is built on SOAR (security orchestration, automation, and response) technology. SOAR platforms are like SIEMs in that they aggregate, correlate, and analyze alerts. However, SOAR technology takes it a step further by integrating threat intelligence and automating incident investigation and response workflows based on playbooks created by the security team.
Source: https://www.cisco.com/c/en/us/products/security/what-is-a-security-platform.html#~types-of-security-platforms
So answer A is correct
8
"A" is correct
Unlike traditional SIEM platforms, SOAR solutions can also be used for threat and vulnerability management, security incident response, and security operations automation.
Example of products:
Log collection (SolarWinds Security Event Manager) -----> SIEM (IBM QRadar) -----> SOAR (IBM Resilient)
A 4
Selected Answer: A
Correct Answer is A: SIEM vs SOAR - In short, SIEM aggregates and correlates data from multiple security systems to generate alerts while SOAR acts as the remediation and response. "Note SIEM from multiple security systems"
A 3
Selected Answer: A
"Unlike traditional SIEM platforms, SOAR solutions can also be used for threat and
vulnerability management, security incident response, and security operations
automation." This sentence is from the Official CertGuide book. pg 461 in the Tip box
2
A IS CORRECT ,SOAR IS USED TO IDENTIFY AND MITIGATE THE VULNERABILITY IT CAN RESPOND ,,,SIEM ONLY LOG MANAGEMENT AND SECURITY MONITORING
B 2
Selected Answer: B
I think the correct answer is B.
A. SOAR platforms are used for threat and vulnerability management, but SIEM applications are not - This statement is not fully accurate. SIEM applications are also used for threat and vulnerability management.
C. SOAR receives information from a single platform and delivers it to a SIEM - This statement is incorrect because SOAR platforms can integrate with multiple security tools, not just one platform.
D. SIEM receives information from a single platform and delivers it to a SOAR - This statement is incorrect because SIEM applications collect and analyze security-related data from multiple sources, not just one platform.
So, only option B correctly describes the relationship between SIEM and SOAR, where SIEM is used for threat and vulnerability management while SOAR is not.
2
SIEMs are used for logging entries from applications, endpoints and servers, and make a nice list for a tech to review,
A SOAR goes a step further by responding to security incidents
2
The answer is D: but how can you say this answer is correct: SOAR platforms are used for threat and vulnerability management, but SIEM applications are not. So what is SIEM used for, to peel potatoes?
But who gave you these answers?
A 2
Selected Answer: A
it is correct
1
The best answer is A. SOAR (Security Orchestration, Automation, and Response) platforms are used for threat and vulnerability management, while SIEM (Security Information and Event Management) applications are mainly used for log and event management. SOAR platforms connect with SIEM systems to get security event data and trigger automated responses based on defined playbooks.
D 1
Selected Answer: D
D is the right answer
1
D is really wrong
1
A. SOAR platforms are used for threat and vulnerability management, but SIEM applications are not
D 1
Selected Answer: D
I believe the correct answer is D
D 1
Selected Answer: D
SIEM (Security Information and Event Management):
Primary Function: Gathers, stores, and analyzes security event logs from different systems to detect threats, provide alerts, and support security teams during incident investigation.
Purpose: SIEM is centered on monitoring, logging, and event correlation. It helps with real-time threat detection and incident response by aggregating logs and delivering insights from the collected data.
SOAR (Security Orchestration, Automation, and Response):
Primary Function: Automates and orchestrates the security response process. It helps security teams react to incidents faster by automating tasks like blocking IP addresses, isolating systems, and running predefined playbooks.
Purpose: SOAR is used to streamline workflows, automate repetitive actions, and integrate with different security tools (including SIEM) to ensure quick and coordinated responses to incidents.