CompTIA Project+ (PK0-005)Basics of IT and GovernanceHard

A project involves implementing a new regulatory compliance framework for data handling across a large enterprise. The project manager needs a solution that can centralize the collection and analysis of security events from various network devices, servers, and applications to detect and respond to threats efficiently. Which IT infrastructure component is BEST suited for this purpose?

  1. AData Loss Prevention (DLP)
  2. BSecurity Information and Event Management (SIEM)
  3. CIntrusion Detection System (IDS)
  4. DFirewall
Show answer & explanation

Correct answer: B. Security Information and Event Management (SIEM)

A Security Information and Event Management (SIEM) system is specifically designed to centralize the collection, correlation, and analysis of security logs and events from across an entire IT infrastructure, enabling real-time threat detection and compliance reporting.

Why the other options are wrong

  • A. DLP systems focus on preventing sensitive data from leaving the organization, not on centralized security event collection and analysis for overall threat detection and compliance.
  • C. An IDS monitors network traffic for suspicious activity but does not centralize logs from all sources or perform comprehensive correlation for compliance.
  • D. A firewall controls network traffic based on rules but does not collect and analyze logs from all infrastructure components for threat detection and compliance.

Security Information and Event Management (SIEM)

A solution that combines security information management (SIM) and security event management (SEM) functions into one security management system. It provides real-time analysis of security alerts generated by network hardware and applications.

  • Centralizes security logs and events.
  • Performs correlation and analysis for threat detection.
  • Supports compliance reporting and incident response.

Memory trick: SIEM sees all events, making sense for security and rules.

More Basics of IT and Governance questions