712-50 · Question #330
In order for a CISO to have true situational awareness there is a need to deploy technology that can give a real-time view of security events across the enterprise. Which tool selection represents…
The correct answer is C. Security Incident Event Management (SIEM), IDS, router, syslog. SIEM (Security Incident Event Management): This is the central hub for collecting, analyzing, and visualizing security logs from various sources across the network, providing a comprehensive view of potential security incidents in real-time. IDS (Intrusion Detection System)…
Question
In order for a CISO to have true situational awareness there is a need to deploy technology that can give a real-time view of security events across the enterprise. Which tool selection represents the BEST choice to achieve situational awareness?
Options
- AVmware, router, switch, firewall, syslog, vulnerability management system (VMS)
- BIntrusion Detection System (IDS), firewall, switch, syslog
- CSecurity Incident Event Management (SIEM), IDS, router, syslog
- DSIEM, IDS, firewall, VMS
How the community answered
(60 responses)- A17% (10)
- B3% (2)
- C72% (43)
- D8% (5)
Explanation
SIEM (Security Incident Event Management): This is the central hub for collecting, analyzing, and visualizing security logs from various sources across the network, providing a comprehensive view of potential security incidents in real-time. IDS (Intrusion Detection System): Detects suspicious network activity that could indicate an attack, providing early warning to the SIEM system. Router and syslog: Routers collect network traffic information which can be logged and sent to the SIEM through syslog, enabling the system to monitor network activity across different
Topics
Community Discussion
No community discussion yet for this question.