Learn to properly scope SOC responsibilities. In this scenario, you will analyze a hybrid SIEM deployment model balancing internal limitations with outsourced security operations.
You are a Security Architect at OmniRetail, an e-commerce company with massive physical distribution centers. You have a small internal IT team capable of managing local infrastructure, but absolutely zero internal capability for 24/7 log correlation, threat hunting, or Tier 1/2 triage. You are reviewing the proposed Statement of Work (SOW) from an MSSP.
Your job is to identify the correct terminology for this specific architectural arrangement.
An organization wants to implement a SIEM deployment architecture. However, they have the capability to do only log collection and the rest of the SIEM functions must be managed by an MSSP. Which SIEM deployment architecture will the organization adopt?
The organization is evaluating architectural models for a new SIEM. They want to retain control over the initial log collection layer (deploying agents and aggregators internally) but lack the SOC maturity to tune, correlate, and respond to alerts. Therefore, they are outsourcing the "brain" and the operational manpower of the SIEM to a Managed Security Service Provider (MSSP).
The organization deploys and maintains the log collection infrastructure within its own environment, making the data gathering portion Self-hosted. Because the organization cannot perform SIEM functions like correlation, dashboarding, or incident triage, those duties are completely offloaded to an external provider, making the operational tier MSSP Managed.
A. Cloud, MSSP Managed: Implies the collection infrastructure is entirely cloud-native or hosted externally without on-prem footprint.
B. Self-hosted, Jointly Managed: Joint management requires the internal team to actively participate in SIEM analysis, tuning, or alert handling. The prompt explicitly states "the rest of the SIEM functions must be managed by an MSSP."
D. Self-hosted, Self-Managed: This represents an entirely in-house SOC where the organization handles both collection and Tier 1/2/3 analysis.
This is a highly common architecture for mid-sized enterprises. Companies want to "own" their raw data and ensure local network traffic (like NetFlow or internal AD logs) doesn't completely saturate their external bandwidth. They use Heavy Forwarders (e.g., Splunk Heavy Forwarder, Logstash) deployed internally to filter and compress logs before shipping them securely to the MSSP for 24/7 "eyes on glass" monitoring.
Modern SIEMs are broken into distinct functional tiers. Understanding these tiers helps define MSSP contracts:
Practice more realistic scenarios to prepare for your EC-Council CSA exam.
Explore more CSA simulations