nerdexam
EC-Council

312-50V13 · Question #185

The tools which receive event logs from servers, network equipment, and applications, and perform analysis and correlation on those logs, and can generate alarms for security relevant issues, are…

The correct answer is D. Security incident and event Monitoring. The question describes tools that collect, analyze, and correlate event logs from various sources to identify security issues and generate alarms.

Submitted by marco_it· Mar 6, 2026Introduction to Ethical Hacking

Question

The tools which receive event logs from servers, network equipment, and applications, and perform analysis and correlation on those logs, and can generate alarms for security relevant issues, are known as what?

Options

  • Anetwork Sniffer
  • BVulnerability Scanner
  • CIntrusion prevention Server
  • DSecurity incident and event Monitoring

How the community answered

(66 responses)
  • A
    2% (1)
  • B
    5% (3)
  • C
    8% (5)
  • D
    86% (57)

Why each option

The question describes tools that collect, analyze, and correlate event logs from various sources to identify security issues and generate alarms.

Anetwork Sniffer

A network sniffer captures and analyzes raw network packets, focusing on network traffic rather than the centralized collection and correlation of system and application logs.

BVulnerability Scanner

A vulnerability scanner identifies known weaknesses and misconfigurations in systems and applications, but it does not primarily collect, analyze, or correlate real-time event logs for ongoing security monitoring.

CIntrusion prevention Server

An Intrusion Prevention System (IPS) actively monitors for and attempts to block malicious activities in real-time, but its main function is prevention, not the comprehensive collection, analysis, and correlation of general event logs.

DSecurity incident and event MonitoringCorrect

Security Information and Event Monitoring (SIEM) systems are specifically designed to aggregate event logs from diverse sources, perform correlation and analysis on this data, and generate alerts for security-relevant incidents, fitting the description perfectly.

Concept tested: Security Information and Event Monitoring (SIEM)

Source: https://learn.microsoft.com/en-us/azure/sentinel/overview

Topics

#SIEM#Log management#Security monitoring#Event correlation

Community Discussion

No community discussion yet for this question.

Full 312-50V13 Practice