nerdexam
Isaca

CISA · Question #202

Which of the following BEST enables an organization's information security team to correlate and aggregate log files from different sources?

The correct answer is B. Security information and event management (SIEM). SIEM (Security Information and Event Management) is purpose-built to collect, normalize, correlate, and aggregate log data from diverse sources - firewalls, endpoints, servers, applications - into a single centralized platform, making it the definitive answer here. An IDS (A) det

Submitted by kevin_r· Apr 18, 2026Protection of Information Assets

Question

Which of the following BEST enables an organization’s information security team to correlate and aggregate log files from different sources?

Options

  • AIntrusion detection system (IDS)
  • BSecurity information and event management (SIEM)
  • CEndpoint security monitoring system
  • DVulnerability and threat management

How the community answered

(29 responses)
  • B
    93% (27)
  • C
    3% (1)
  • D
    3% (1)

Explanation

SIEM (Security Information and Event Management) is purpose-built to collect, normalize, correlate, and aggregate log data from diverse sources - firewalls, endpoints, servers, applications - into a single centralized platform, making it the definitive answer here.

An IDS (A) detects suspicious network or host activity but does not aggregate logs from multiple disparate sources - it monitors traffic, not log management. An Endpoint security monitoring system (C) is scoped to individual devices and lacks the cross-source aggregation capability. Vulnerability and threat management (D) focuses on identifying and prioritizing weaknesses, not on log collection or correlation.

Memory tip: Think of SIEM as a "security flight recorder" - it pulls in every log from every system and lets analysts replay and correlate events across the entire environment. If the question mentions multiple sources, correlation, or aggregation of logs, SIEM is almost always the answer.

Topics

#SIEM#Log Management#Security Monitoring#Event Correlation

Community Discussion

No community discussion yet for this question.

Full CISA Practice