nerdexam
CompTIA

CS0-003 · Question #215

Security analysts review logs on multiple servers on a daily basis. Which of the following implementations will give the best central visibility into the events occurring throughout the corporate…

The correct answer is B. Configure the servers to forward logs to a SIEM. The best implementation to give the best central visibility into the events occurring throughout the corporate environment without logging in to the servers individually is B. Configure the servers to forward logs to a SIEM. A SIEM (Security Information and Event Management) is…

Submitted by cyberguy42· Mar 6, 2026Security Operations

Question

Security analysts review logs on multiple servers on a daily basis. Which of the following implementations will give the best central visibility into the events occurring throughout the corporate environment without logging in to the servers individually?

Options

  • ADeploy a database to aggregate the logging
  • BConfigure the servers to forward logs to a SIEM
  • CShare the log directory on each server to allow local access.
  • DAutomate the emailing of logs to the analysts.

How the community answered

(46 responses)
  • A
    4% (2)
  • B
    93% (43)
  • D
    2% (1)

Explanation

The best implementation to give the best central visibility into the events occurring throughout the corporate environment without logging in to the servers individually is B. Configure the servers to forward logs to a SIEM. A SIEM (Security Information and Event Management) is a security solution that helps organizations detect, analyze, and respond to security threats before they disrupt business. SIEM tools collect, aggregate, and correlate log data from various sources across an organization's network, such as applications, devices, servers, and users. SIEM tools also provide real-time alerts, dashboards, reports, and incident response capabilities to help security teams identify and mitigate cyberattacks. By configuring the servers to forward logs to a SIEM, the security analysts can have a central view of potential threats and monitor security incidents across the corporate environment without logging in to the servers individually. This can save time, improve efficiency, and enhance security posture. Deploying a database to aggregate the logging (A) may not provide the same level of analysis, correlation, and alerting as a SIEM tool. Sharing the log directory on each server to allow local access © may not be scalable or secure for a large number of servers. Automating the emailing of logs to the analysts (D) may not be timely or effective for real-time threat detection and response. Therefore, B is the best option among the choices given.

Topics

#SIEM#centralized logging#security monitoring#log aggregation

Community Discussion

No community discussion yet for this question.

Full CS0-003 Practice