nerdexam
LPI

303-300 · Question #92

Which of the following is an example of an HID tool?

The correct answer is C. Security information and event management (SIEM) system. A SIEM system qualifies as an HID (Host Intrusion Detection) tool because it aggregates, correlates, and analyzes log and event data from hosts, applications, and network devices across the enterprise to detect security incidents - making detection its core purpose. Why the…

Threat Detection and Incident Response

Question

Which of the following is an example of an HID tool?

Options

  • AAntivirus software
  • BFirewall
  • CSecurity information and event management (SIEM) system
  • DIntrusion prevention system (IPS)

How the community answered

(52 responses)
  • A
    2% (1)
  • B
    2% (1)
  • C
    90% (47)
  • D
    6% (3)

Explanation

A SIEM system qualifies as an HID (Host Intrusion Detection) tool because it aggregates, correlates, and analyzes log and event data from hosts, applications, and network devices across the enterprise to detect security incidents - making detection its core purpose.

Why the distractors are wrong:

  • A (Antivirus): An endpoint protection tool that identifies and removes malware; it prevents/remedies threats rather than detecting and correlating events across the environment.
  • B (Firewall): A network access control tool that filters traffic based on rules; it enforces boundaries but doesn't analyze host-level security events.
  • D (IPS): An Intrusion Prevention System actively blocks malicious traffic in real time - it's in the "prevention" category, not the "detection" category, and operates at the network layer rather than aggregating host-based data.

Memory tip: Contrast the acronyms - IPS = Stops it, SIEM = Sees it. SIEM is the passive observer that collects and correlates; IPS is the active blocker. When a question asks about a tool focused on visibility and detection across multiple sources, SIEM is your answer.

Topics

#HID tools#SIEM systems#Security monitoring#Threat detection

Community Discussion

No community discussion yet for this question.

Full 303-300 Practice