SOC wants agent activity in the SIEM. What should be ensured?
Select an answer to reveal the explanation.
Short Explanation
SIEM needs logs. Keep agent activity and audit flowing — sticky notes don't page on-call.
Full Explanation
Correct Answer — A
Security operations depend on exporting/retaining agent and directory audit signals into SIEM for detection and response.
Why B is wrong: Blinds SOC.
Why C is wrong: Not scalable/secure.
Why D is wrong: Not durable evidence.
Exam tip: Agent activity to SIEM → logging + integration.