CompTIA CySA+ CS0-003 Practice Question
An organization wants to ensure that their SIEM system is optimized for quick detection and analysis of security incidents. What is the BEST approach to achieve this goal?
Generate scheduled reports for manual review every 24 hours.
Enable event correlation rules to identify related activities across multiple log sources.
Invest in a faster processing server to handle an increased volume of security data.
Increase the storage capacity to accommodate more log data.