312-49 · Question #497
Company ABC has employed a firewall, IDS, Antivirus, Domain Controller, and SIEM. The company's domain controller goes down. From which system would you begin your investigation?
The correct answer is C. SIEM. A Security Information and Event Management (SIEM) system aggregates and correlates logs from all other security and infrastructure components - including the Domain Controller, Firewall, IDS, and Antivirus. Because the Domain Controller is already down, you cannot directly…
Question
Company ABC has employed a firewall, IDS, Antivirus, Domain Controller, and SIEM. The company's domain controller goes down. From which system would you begin your investigation?
Options
- ADomain Controller
- BFirewall
- CSIEM
- DIDS
How the community answered
(54 responses)- A9% (5)
- B2% (1)
- C83% (45)
- D6% (3)
Explanation
A Security Information and Event Management (SIEM) system aggregates and correlates logs from all other security and infrastructure components - including the Domain Controller, Firewall, IDS, and Antivirus. Because the Domain Controller is already down, you cannot directly query it for logs. The SIEM, however, will have ingested and stored its log data prior to the outage, making it the best starting point to reconstruct the timeline of events, identify the root cause, and correlate activity across the environment.
Topics
Community Discussion
No community discussion yet for this question.