nerdexam
EC-Council

712-50 · Question #330

In order for a CISO to have true situational awareness there is a need to deploy technology that can give a real-time view of security events across the enterprise. Which tool selection represents…

The correct answer is C. Security Incident Event Management (SIEM), IDS, router, syslog. SIEM (Security Incident Event Management): This is the central hub for collecting, analyzing, and visualizing security logs from various sources across the network, providing a comprehensive view of potential security incidents in real-time. IDS (Intrusion Detection System)…

Information Security Core Competencies

Question

In order for a CISO to have true situational awareness there is a need to deploy technology that can give a real-time view of security events across the enterprise. Which tool selection represents the BEST choice to achieve situational awareness?

Options

  • AVmware, router, switch, firewall, syslog, vulnerability management system (VMS)
  • BIntrusion Detection System (IDS), firewall, switch, syslog
  • CSecurity Incident Event Management (SIEM), IDS, router, syslog
  • DSIEM, IDS, firewall, VMS

How the community answered

(60 responses)
  • A
    17% (10)
  • B
    3% (2)
  • C
    72% (43)
  • D
    8% (5)

Explanation

SIEM (Security Incident Event Management): This is the central hub for collecting, analyzing, and visualizing security logs from various sources across the network, providing a comprehensive view of potential security incidents in real-time. IDS (Intrusion Detection System): Detects suspicious network activity that could indicate an attack, providing early warning to the SIEM system. Router and syslog: Routers collect network traffic information which can be logged and sent to the SIEM through syslog, enabling the system to monitor network activity across different

Topics

#SIEM#situational awareness#security monitoring#IDS

Community Discussion

No community discussion yet for this question.

Full 712-50 Practice