An organization uses a monitoring system that can log security incidents and alert the IT team about potential threats. However, this system does not have the capability to automatically respond to or mitigate these threats. What type of system is being described?
Pick an option to open the notes on all of them.
Key and notes on every option
Key: A
- ACorrect: A SIEM collects and correlates logs and raises alerts, but acting on them automatically is the job of SOAR (or an IPS/EDR), which fits a system that logs and alerts but doesn't respond.
- BA honeypot is a decoy built to attract and study attackers; it doesn't monitor the organization's own systems and send them alerts.
- CA firewall enforces traffic rules by allowing or blocking traffic, which is itself a mitigating action, and it isn't a central incident logging and alerting system.
- DAn IPS can block traffic automatically, which is the capability the stem says this system lacks.