312-50V10 · Question #734
The tools which receive event logs from servers, network equipment, and applications, and perform analysis and correlation on those logs, and can generate alarms for security relevant issues, are know
The correct answer is D. Security Incident and Event Monitoring. Security Information and Event Management (SIEM) tools collect, aggregate, and correlate logs from across the environment to detect and alert on security-relevant events.
Question
The tools which receive event logs from servers, network equipment, and applications, and perform analysis and correlation on those logs, and can generate alarms for security relevant issues, are known as what?
Options
- ANetwork Sniffer
- BVulnerability Scanner
- CIntrusion Prevention Server
- DSecurity Incident and Event Monitoring
How the community answered
(37 responses)- A3% (1)
- B3% (1)
- C8% (3)
- D86% (32)
Why each option
Security Information and Event Management (SIEM) tools collect, aggregate, and correlate logs from across the environment to detect and alert on security-relevant events.
A network sniffer captures raw network packets for traffic analysis but does not aggregate logs from multiple sources or perform event correlation.
A vulnerability scanner probes systems to identify weaknesses and misconfigurations but does not collect or correlate operational event logs.
An Intrusion Prevention System (IPS) monitors and actively blocks malicious network traffic in real time but does not perform broad log aggregation and correlation across diverse sources.
SIEM platforms ingest event logs from servers, network devices, and applications, then apply correlation rules and analytics to identify suspicious patterns. When a potential security incident is detected, the SIEM generates alerts for security analysts to investigate, making it the technology that matches all characteristics described in the question.
Concept tested: SIEM log aggregation, correlation, and alerting
Source: https://csrc.nist.gov/glossary/term/security_information_and_event_management
Topics
Community Discussion
No community discussion yet for this question.