CompTIA CySA+ (CS0-003)Security OperationsEasy

A SOC is redesigning its logging strategy and must decide whether analysts should review logs directly on each individual firewall and server or forward all logs to a centralized SIEM platform. Which of the following is the PRIMARY benefit of forwarding logs to a centralized SIEM?

  1. AIt eliminates the need for a log retention policy
  2. BIt enables correlation of events across multiple sources to detect multi-stage attacks
  3. CIt reduces the total disk space required to store logs long term
  4. DIt automatically patches vulnerabilities identified in the logs
Show answer & explanation

Correct answer: B. It enables correlation of events across multiple sources to detect multi-stage attacks

Centralizing logs in a SIEM allows an analyst to correlate related events from different systems (e.g., a failed VPN login followed by a suspicious internal file access) that would otherwise appear unrelated when viewed in isolation. Storage, retention, and patching are unrelated to the core value of correlation.

Why the other options are wrong

  • A. Retention policies are still required regardless of centralization.
  • C. Centralization does not inherently reduce storage needs and may increase them.
  • D. SIEMs detect and alert; they do not patch vulnerabilities.

SIEM Log Correlation

A SIEM aggregates logs from multiple sources so an analyst can correlate related events and detect attack patterns that span systems.

  • Centralization enables cross-source correlation
  • Correlation reveals multi-stage attacks
  • SIEMs do not remediate vulnerabilities automatically

Memory trick: One big picture beats many puzzle pieces.

More Security Operations questions