Which SIEM feature allows automated responses to specific alert conditions, such as blocking an IP after repeated failed logins?
-
A
Log normalization
-
B
Security Orchestration, Automation, and Response (SOAR) integration
-
C
Data retention policies
-
D
Threat modeling