SY0-701 · Question #789
Which of the following is the most likely reason a security analyst would review SIEM logs?
D - To see correlations across multiple hosts is correct. SIEM (Security Information and Event Management) is purpose-built to aggregate logs from diverse sources - firewalls, endpoints, servers, applications - and correlate events across them. A single suspicious event on one ho
Question
Options
- ATo check for recent password reset attempts
- BTo monitor for potential DDoS attacks
- CTo assess the scope of a privacy breach
- DTo see correlations across multiple hosts
Explanation
D - To see correlations across multiple hosts is correct.
SIEM (Security Information and Event Management) is purpose-built to aggregate logs from diverse sources - firewalls, endpoints, servers, applications - and correlate events across them. A single suspicious event on one host may be meaningless; the same pattern appearing across 50 hosts simultaneously signals a real threat. Correlation is the SIEM's defining capability and the primary reason analysts use it over reviewing individual device logs.
Why the distractors are wrong:
- A (password resets): Too narrow - analysts would check an IAM or Active Directory log directly for this single-system task; SIEM is overkill.
- B (DDoS monitoring): DDoS detection is primarily handled by network monitoring tools, firewalls, or dedicated DDoS mitigation platforms, not SIEM.
- C (privacy breach scope): Assessing a breach's scope is a valid SIEM use case, but it's a downstream outcome of correlation - it's not the primary reason analysts review SIEM logs day-to-day.
Memory tip: Think of SIEM as a "many-to-one" tool - it takes logs from many sources and funnels them into one correlated view. Any answer that describes a single-system task (one log, one host) is probably not the best reason to use SIEM.
Topics
Community Discussion
No community discussion yet for this question.