CISA · Question #202
Which of the following BEST enables an organization's information security team to correlate and aggregate log files from different sources?
The correct answer is B. Security information and event management (SIEM). SIEM (Security Information and Event Management) is purpose-built to collect, normalize, correlate, and aggregate log data from diverse sources - firewalls, endpoints, servers, applications - into a single centralized platform, making it the definitive answer here. An IDS (A) det
Question
Which of the following BEST enables an organization’s information security team to correlate and aggregate log files from different sources?
Options
- AIntrusion detection system (IDS)
- BSecurity information and event management (SIEM)
- CEndpoint security monitoring system
- DVulnerability and threat management
How the community answered
(29 responses)- B93% (27)
- C3% (1)
- D3% (1)
Explanation
SIEM (Security Information and Event Management) is purpose-built to collect, normalize, correlate, and aggregate log data from diverse sources - firewalls, endpoints, servers, applications - into a single centralized platform, making it the definitive answer here.
An IDS (A) detects suspicious network or host activity but does not aggregate logs from multiple disparate sources - it monitors traffic, not log management. An Endpoint security monitoring system (C) is scoped to individual devices and lacks the cross-source aggregation capability. Vulnerability and threat management (D) focuses on identifying and prioritizing weaknesses, not on log collection or correlation.
Memory tip: Think of SIEM as a "security flight recorder" - it pulls in every log from every system and lets analysts replay and correlate events across the entire environment. If the question mentions multiple sources, correlation, or aggregation of logs, SIEM is almost always the answer.
Topics
Community Discussion
No community discussion yet for this question.