147k views
5 votes
The network security manager of a large corporation is planning to improve the efficiency of the company's Security Information and Event Management (SIEM) system. The SIEM system receives data from various sources, including Windows and Linux hosts, switches, routers, and firewalls. To make the data from different sources more consistent and searchable, which functionality should the manager focus on enhancing in the SIEM system?

a. Data Encryption
b. Data Compression
c. Data Normalization
d. Data Redundancy

2 Answers

5 votes

Final answer:

To improve the efficiency of a company's SIEM system by making data from various sources more consistent and searchable, the network security manager should enhance the data normalization functionality.

Step-by-step explanation:

The network security manager should focus on enhancing the data normalization functionality of the Security Information and Event Management (SIEM) system. Data normalization is the process of standardizing and formatting data from various sources into a common format, making it easier to search, correlate, and analyze. By normalizing data, the SIEM system can more efficiently process and compare logs and events from different systems such as Windows and Linux hosts, network devices like switches and routers, and security devices like firewalls, leading to quicker detection of potential security incidents.

User Febin Peter
by
8.0k points
3 votes

Final answer:

The network security manager should focus on enhancing Data Normalization in the SIEM system to make the data from different sources more consistent and searchable.

Step-by-step explanation:

The network security manager should focus on enhancing Data Normalization in the SIEM system to make the data from different sources more consistent and searchable. Data normalization is the process of organizing data in a database so that it is well-structured, eliminating redundancy, and ensuring data integrity. By normalizing the data, the security manager can reduce the complexity of querying and analyzing the data, making it easier to identify security events or anomalies.

Data encryption, data compression, and data redundancy are important aspects of network security but do not directly address the issue of making data from different sources more consistent and searchable.

User Zulfe
by
7.8k points