ISC2 Certified in Cybersecurity (CC)Network SecurityMedium
A security analyst is investigating a suspected intrusion on the corporate network. They observe unusual outbound traffic patterns and multiple failed login attempts on a critical server. To gain real-time visibility into these activities and correlate events from various network devices and applications, which security solution should the analyst primarily rely on?
- AFirewall
- BIntrusion Detection System (IDS)
- CAntivirus Software
- DSecurity Information and Event Management (SIEM)
Show answer & explanationAnswer & explanation
Correct answer: D. Security Information and Event Management (SIEM)
A SIEM system collects, aggregates, and correlates log data and security events from various sources across the network, providing a centralized platform for real-time monitoring, incident detection, and analysis of security incidents.
Why the other options are wrong
- A. A firewall controls network access but doesn't correlate events or provide comprehensive security intelligence.
- B. An IDS detects malicious activity but typically doesn't aggregate and correlate logs from diverse sources like a SIEM.
- C. Antivirus software protects endpoints from malware but doesn't provide network-wide event correlation.
Security Information and Event Management (SIEM)
A security solution that centralizes the collection, storage, and analysis of security logs and events from across an organization's IT infrastructure to provide real-time threat detection and compliance reporting.
- Aggregates logs from various sources (servers, firewalls, applications).
- Correlates security events to identify patterns and potential incidents.
- Provides real-time monitoring and alerting.
- Aids in compliance reporting and forensic investigations.
Memory trick: SIEM is the 'brain' of security, collecting all the 'eyes and ears' data to spot trouble.