Tools / Cyber Security Interview Questions
What is a Security Information and Event Management (SIEM) system?
A SIEM system collects log and event data from across an organization's servers, network devices, applications, and endpoints, then correlates it to detect suspicious patterns in near real time.
- Centralizes logs from firewalls, servers, endpoints, and cloud services
- Applies correlation rules to flag combinations of events that look like an attack
- Provides dashboards and alerts for security analysts
- Retains historical data to support investigations and compliance audits
Popular examples include Splunk, IBM QRadar, and Microsoft Sentinel; a SIEM is typically the core tool used inside a Security Operations Center (SOC).
More Related questions...