GK Question

technology medium mcq

Which SOC component correlates alerts from multiple sources to identify advanced threats?

  1. SIEM
  2. SOAR
  3. EDR
  4. All of these

Answer: SIEM

SIEM (Security Information and Event Management) aggregates logs, correlates events, and detects anomalies across network, endpoint, and application sources. Foundation for modern SOC operations.

Topic Cybersecurity Operations
Exam Relevance Banking, UPSC, SSC