Correct Answer: Selectively logged connection events on security-relevant rules, regularly reviewed discovery events for new hosts/applications, and periodic trend analysis of aggregated data to inform both investigations and capacity planning
Explanation: Effective SOC visibility combines selective connection logging, regular discovery event review, and periodic trend analysis, unlike relying solely on intrusion events, logging everything with no discovery review, annual-only discovery review with no connection logging, collecting but never reviewing events, or trend analysis alone with no individual event review for investigations.
Correct Answer: Selectively logged connection events on security-relevant rules, regularly reviewed discovery events for new hosts/applications, and periodic trend analysis of aggregated data to inform both investigations and capacity planning
Explanation: Effective SOC visibility combines selective connection logging, regular discovery event review, and periodic trend analysis, unlike relying solely on intrusion events, logging everything with no discovery review, annual-only discovery review with no connection logging, collecting but never reviewing events, or trend analysis alone with no individual event review for investigations.