CompTIA Project+ (PK0-005)Basics of IT and GovernanceHard

A project involves implementing a new regulatory compliance framework for data handling. The framework requires strict logging and auditing of all access to sensitive customer data. Which IT infrastructure component is most critical for collecting and centralizing these logs from various systems?

  1. AVirtual Private Network (VPN)
  2. BSecurity Information and Event Management (SIEM) system
  3. CStorage Area Network (SAN)
  4. DContent Delivery Network (CDN)
Show answer & explanation

Correct answer: B. Security Information and Event Management (SIEM) system

A SIEM system is specifically designed to collect, centralize, and analyze security logs and events from various sources across an IT infrastructure, which is critical for meeting strict logging and auditing requirements for compliance.

Why the other options are wrong

  • A. A VPN provides secure, encrypted connections over a public network, not for log collection and analysis.
  • C. A SAN provides high-speed block-level storage, unrelated to collecting and analyzing logs.
  • D. A CDN improves content delivery speed by caching, not for log collection.

Security Information and Event Management (SIEM)

A software solution that aggregates and analyzes security alerts from different applications and network hardware in real-time.

  • Centralizes logs from various sources.
  • Provides real-time analysis of security events.
  • Crucial for compliance auditing and incident response.

Memory trick: For compliance, gather all the security clues in one place and analyze them.

More Basics of IT and Governance questions