Which SOC component correlates alerts from multiple sources to identify advanced threats?
- SIEM
- SOAR
- EDR
- All of these
Answer: SIEM
SIEM (Security Information and Event Management) aggregates logs, correlates events, and detects anomalies across network, endpoint, and application sources. Foundation for modern SOC operations.