Palo Alto Networks Certified Security Automation Engineer (PCSAE) — Question 44

What is the most effective way to correlate multiple raw events coming from a SIEM and link them together?

Answer options

Correct answer: C

Explanation

The correct answer is C because configuring a pre-process rule allows for real-time linking of related events as they are ingested, enhancing efficiency. Option A involves post-processing, which is less immediate, while B requires custom scripting that may not be necessary. Option D is the least effective as it relies on manual intervention, which is time-consuming and prone to error.