CAS-005 · Question #48
An audit finding reveals that a legacy platform has not retained logs for more than 30 days. The platform has been segmented due to its interoperability with newer technology. As a temporary…
The correct answer is C. Configure the SIEM to aggregate the logs. A SIEM (Security Information and Event Management) solution is specifically designed to collect, store, and aggregate logs from various systems. By configuring the SIEM to aggregate the logs, the security engineer can ensure that the logs are properly retained, analyzed, and…
Question
An audit finding reveals that a legacy platform has not retained logs for more than 30 days. The platform has been segmented due to its interoperability with newer technology. As a temporary solution, the IT department changed the log retention to 120 days. Which of the following should the security engineer do to ensure the logs are being properly retained?
Options
- AConfigure a scheduled task nightly to save the logs
- BConfigure event-based triggers to export the logs at a threshold.
- CConfigure the SIEM to aggregate the logs
- DConfigure a Python script to move the logs into a SQL database.
How the community answered
(15 responses)- A7% (1)
- B7% (1)
- C73% (11)
- D13% (2)
Explanation
A SIEM (Security Information and Event Management) solution is specifically designed to collect, store, and aggregate logs from various systems. By configuring the SIEM to aggregate the logs, the security engineer can ensure that the logs are properly retained, analyzed, and correlated for compliance and security purposes. This solution provides long-term storage and easier access to logs for investigations.
Community Discussion
No community discussion yet for this question.