SOC wants agent activity in the SIEM. What should be ensured?
Select an answer to reveal the explanation.
Short Explanation and Infographic
SIEM needs logs. Keep agent activity and audit flowing — sticky notes don't page on-call.
Full explanation below image
Full Explanation
Correct Answer — A
Security operations depend on exporting/retaining agent and directory audit signals into SIEM for detection and response.
Why B is wrong: Blinds SOC.
Why C is wrong: Not scalable/secure.
Why D is wrong: Not durable evidence.
Exam tip: Agent activity to SIEM → logging + integration.