nerdexam
Cisco

350-201 · Question #89

How is a SIEM tool used?

The correct answer is D. To collect and analyze security data from network devices and servers and produce alerts. A SIEM collects and aggregates security event data from across the environment, analyzes it for threats and anomalies, and produces alerts for security teams to investigate.

Security Monitoring

Question

How is a SIEM tool used?

Options

  • ATo collect security data from authentication failures and cyber attacks and forward it for analysis
  • BTo search and compare security data against acceptance standards and generate reports for
  • CTo compare security alerts against configured scenarios and trigger system responses
  • DTo collect and analyze security data from network devices and servers and produce alerts

How the community answered

(46 responses)
  • A
    2% (1)
  • B
    4% (2)
  • C
    7% (3)
  • D
    87% (40)

Why each option

A SIEM collects and aggregates security event data from across the environment, analyzes it for threats and anomalies, and produces alerts for security teams to investigate.

ATo collect security data from authentication failures and cyber attacks and forward it for analysis

Simply forwarding collected data for external analysis describes a log aggregator or syslog forwarder - a SIEM performs its own correlation and analysis internally rather than delegating analysis elsewhere.

BTo search and compare security data against acceptance standards and generate reports for

Comparing data against acceptance standards and generating compliance reports describes a vulnerability management or compliance scanning tool, not a SIEM, which is focused on real-time threat detection.

CTo compare security alerts against configured scenarios and trigger system responses

Comparing alerts against configured scenarios and triggering automated system responses describes a SOAR (Security Orchestration, Automation, and Response) platform - a SIEM produces alerts but does not natively orchestrate automated remediation workflows.

DTo collect and analyze security data from network devices and servers and produce alertsCorrect

A SIEM ingests log and event data from network devices, servers, endpoints, and security tools, then correlates and analyzes this data using rules and behavioral analytics to identify potential security threats. When suspicious patterns are detected, the SIEM generates prioritized alerts that enable security analysts to investigate and respond in a timely manner. This dual function of centralized collection combined with real-time analysis and alerting output is the defining operational characteristic of a SIEM platform.

Concept tested: SIEM tool core purpose and functionality

Source: https://www.cisco.com/c/en/us/products/security/what-is-siem.html

Topics

#SIEM#log analysis#security alerts#network monitoring

Community Discussion

No community discussion yet for this question.

Full 350-201 Practice