312-50V13 · Question #185
The tools which receive event logs from servers, network equipment, and applications, and perform analysis and correlation on those logs, and can generate alarms for security relevant issues, are…
The correct answer is D. Security incident and event Monitoring. The question describes tools that collect, analyze, and correlate event logs from various sources to identify security issues and generate alarms.
Question
Options
- Anetwork Sniffer
- BVulnerability Scanner
- CIntrusion prevention Server
- DSecurity incident and event Monitoring
How the community answered
(66 responses)- A2% (1)
- B5% (3)
- C8% (5)
- D86% (57)
Why each option
The question describes tools that collect, analyze, and correlate event logs from various sources to identify security issues and generate alarms.
A network sniffer captures and analyzes raw network packets, focusing on network traffic rather than the centralized collection and correlation of system and application logs.
A vulnerability scanner identifies known weaknesses and misconfigurations in systems and applications, but it does not primarily collect, analyze, or correlate real-time event logs for ongoing security monitoring.
An Intrusion Prevention System (IPS) actively monitors for and attempts to block malicious activities in real-time, but its main function is prevention, not the comprehensive collection, analysis, and correlation of general event logs.
Security Information and Event Monitoring (SIEM) systems are specifically designed to aggregate event logs from diverse sources, perform correlation and analysis on this data, and generate alerts for security-relevant incidents, fitting the description perfectly.
Concept tested: Security Information and Event Monitoring (SIEM)
Source: https://learn.microsoft.com/en-us/azure/sentinel/overview
Topics
Community Discussion
No community discussion yet for this question.