nerdexam
(ISC)2

CISSP · Question #1293

Which of the following would be considered an incident if reported by a security information and event management (SIEM) system?

The correct answer is B. A log source has stopped sending data. A log source is a device or system that generates and sends data to a security information and event management (SIEM) system, such as logs, alerts, or events. A log source that has stopped sending data would be considered an incident if reported by a SIEM system, as this could…

Submitted by lukas.cz· Mar 5, 2026Security Operations

Question

Which of the following would be considered an incident if reported by a security information and event management (SIEM) system?

Options

  • AAn administrator is logging in on a server through a virtual private network (VPN).
  • BA log source has stopped sending data.
  • CA web resource has reported a 404 error.
  • DA firewall logs a connection between a client on the Internet and a web server using Transmission

How the community answered

(27 responses)
  • A
    4% (1)
  • B
    85% (23)
  • C
    7% (2)
  • D
    4% (1)

Explanation

A log source is a device or system that generates and sends data to a security information and event management (SIEM) system, such as logs, alerts, or events. A log source that has stopped sending data would be considered an incident if reported by a SIEM system, as this could indicate a malfunction, a compromise, or a denial of service attack on the log source. A SIEM system relies on the data from the log sources to provide a comprehensive and accurate view of the security posture and events of the organization. An administrator logging in on a server through a virtual private network (VPN) would not be considered an incident, as this is a legitimate and authorized activity. A web resource reporting a 404 error would not be considered an incident, as this is a common and benign error that indicates that the requested resource was not found on the server. A firewall logging a connection between a client on the Internet and a web server using Transmission Control Protocol (TCP) on port 80 would not be considered an incident, as this is a normal and expected traffic for web browsing.

Topics

#Security incident#SIEM alerts#Log monitoring#Incident detection

Community Discussion

No community discussion yet for this question.

Full CISSP Practice