What is the purpose of a SIEM (Security Information and Event Management) system?
- A.To collect, correlate, and analyze security event data from multiple sources for real-time monitoring and alerting
- B.To replace firewalls
- C.To manage user accounts, which Requirement 8.3.4 protects by locking the account after no more than ten invalid attempts, for at least thirty minutes or until identity is verified
- D.To encrypt stored data, which Requirement 3.5.1 requires to be rendered unreadable anywhere it is stored, whether by truncation, tokens, keyed hashing, or strong cryptography
Why A is correct
SIEM systems aggregate and correlate security event data from across the CDE, enabling centralized monitoring, alerting, and forensic analysis.
Know someone studying for PCI DSS? Send them this one.