CS0-003 · Question #491
An organization plans to use an advanced machine-learning tool as a central collection server. The tool will perform data aggregation and analysis. Which of the following should the organization…
The correct answer is A. SIEM. For advanced data aggregation, analysis, and machine learning from diverse sources, a Security Information and Event Management (SIEM) system is the most appropriate implementation.
Question
An organization plans to use an advanced machine-learning tool as a central collection server. The tool will perform data aggregation and analysis. Which of the following should the organization implement?
Options
- ASIEM
- BFirewalls
- CSyslog server
- DFlow analysis
How the community answered
(31 responses)- A94% (29)
- B3% (1)
- C3% (1)
Why each option
For advanced data aggregation, analysis, and machine learning from diverse sources, a Security Information and Event Management (SIEM) system is the most appropriate implementation.
A SIEM system is designed to collect, aggregate, and analyze log data and security events from various sources across an organization's IT infrastructure, often incorporating advanced analytics and machine learning capabilities to detect threats and manage security incidents proactively.
Firewalls primarily control network traffic based on rules and do not perform advanced data aggregation or machine learning for security analysis across an enterprise.
A Syslog server is a basic log collection point but lacks the advanced aggregation, analysis, and machine learning capabilities needed for a central collection server performing data analysis.
Flow analysis focuses on network traffic metadata (e.g., NetFlow, IPFIX) to identify patterns but does not encompass the broader log and event data aggregation and advanced analytical capabilities described.
Concept tested: SIEM capabilities for security data aggregation and analysis
Source: https://learn.microsoft.com/en-us/azure/sentinel/overview
Topics
Community Discussion
No community discussion yet for this question.