nerdexam
EC-Council

312-50V10 · Question #734

The tools which receive event logs from servers, network equipment, and applications, and perform analysis and correlation on those logs, and can generate alarms for security relevant issues, are know

The correct answer is D. Security Incident and Event Monitoring. Security Information and Event Management (SIEM) tools collect, aggregate, and correlate logs from across the environment to detect and alert on security-relevant events.

Information Security and Ethical Hacking Fundamentals

Question

The tools which receive event logs from servers, network equipment, and applications, and perform analysis and correlation on those logs, and can generate alarms for security relevant issues, are known as what?

Options

  • ANetwork Sniffer
  • BVulnerability Scanner
  • CIntrusion Prevention Server
  • DSecurity Incident and Event Monitoring

How the community answered

(37 responses)
  • A
    3% (1)
  • B
    3% (1)
  • C
    8% (3)
  • D
    86% (32)

Why each option

Security Information and Event Management (SIEM) tools collect, aggregate, and correlate logs from across the environment to detect and alert on security-relevant events.

ANetwork Sniffer

A network sniffer captures raw network packets for traffic analysis but does not aggregate logs from multiple sources or perform event correlation.

BVulnerability Scanner

A vulnerability scanner probes systems to identify weaknesses and misconfigurations but does not collect or correlate operational event logs.

CIntrusion Prevention Server

An Intrusion Prevention System (IPS) monitors and actively blocks malicious network traffic in real time but does not perform broad log aggregation and correlation across diverse sources.

DSecurity Incident and Event MonitoringCorrect

SIEM platforms ingest event logs from servers, network devices, and applications, then apply correlation rules and analytics to identify suspicious patterns. When a potential security incident is detected, the SIEM generates alerts for security analysts to investigate, making it the technology that matches all characteristics described in the question.

Concept tested: SIEM log aggregation, correlation, and alerting

Source: https://csrc.nist.gov/glossary/term/security_information_and_event_management

Topics

#SIEM#event logging#security monitoring#log correlation

Community Discussion

No community discussion yet for this question.

Full 312-50V10 Practice