nerdexam
Cisco

210-250 · Question #49

Which definition describes the main purpose of a Security Information and Event Management solution ?

The correct answer is D. a security product that collects, normalizes, and correlates event log data to provide holistic views. A SIEM solution aggregates, normalizes, and correlates log and event data from across an environment to give security teams a unified, actionable view of security posture.

Security Technologies

Question

Which definition describes the main purpose of a Security Information and Event Management solution ?

Options

  • Aa database that collects and categorizes indicators of compromise to evaluate and search for
  • Ba monitoring interface that manages firewall access control lists for duplicate firewall filtering
  • Ca relay server or device that collects then forwards event logs to another log collection device
  • Da security product that collects, normalizes, and correlates event log data to provide holistic views

How the community answered

(55 responses)
  • A
    5% (3)
  • B
    2% (1)
  • C
    2% (1)
  • D
    91% (50)

Why each option

A SIEM solution aggregates, normalizes, and correlates log and event data from across an environment to give security teams a unified, actionable view of security posture.

Aa database that collects and categorizes indicators of compromise to evaluate and search for

A database of indicators of compromise (IOCs) describes a threat intelligence platform, not a SIEM.

Ba monitoring interface that manages firewall access control lists for duplicate firewall filtering

Managing firewall access control lists describes a firewall management system or a security policy manager, not a SIEM.

Ca relay server or device that collects then forwards event logs to another log collection device

Forwarding logs to another collection device describes a syslog relay or log aggregator, which lacks the normalization and correlation capabilities of a SIEM.

Da security product that collects, normalizes, and correlates event log data to provide holistic viewsCorrect

A SIEM collects event logs from diverse sources such as firewalls, endpoints, and applications, then normalizes the data into a common format and applies correlation rules to identify patterns indicative of threats. This holistic, correlated view is what distinguishes a SIEM from simpler logging or monitoring tools.

Concept tested: SIEM definition - log collection, normalization, and correlation

Source: https://csrc.nist.gov/publications/detail/sp/800-92/final

Topics

#SIEM#log correlation#event management#security monitoring

Community Discussion

No community discussion yet for this question.

Full 210-250 Practice