ISC2 Certified in Cybersecurity (CC)Network SecurityMedium

A security analyst is investigating a suspected intrusion on the corporate network. They observe unusual outbound traffic patterns and multiple failed login attempts on a critical server. To gain real-time visibility into these activities and correlate events from various network devices and applications, which security solution should the analyst primarily rely on?

  1. AFirewall
  2. BIntrusion Detection System (IDS)
  3. CAntivirus Software
  4. DSecurity Information and Event Management (SIEM)
Show answer & explanation

Correct answer: D. Security Information and Event Management (SIEM)

A SIEM system collects, aggregates, and correlates log data and security events from various sources across the network, providing a centralized platform for real-time monitoring, incident detection, and analysis of security incidents.

Why the other options are wrong

  • A. A firewall controls network access but doesn't correlate events or provide comprehensive security intelligence.
  • B. An IDS detects malicious activity but typically doesn't aggregate and correlate logs from diverse sources like a SIEM.
  • C. Antivirus software protects endpoints from malware but doesn't provide network-wide event correlation.

Security Information and Event Management (SIEM)

A security solution that centralizes the collection, storage, and analysis of security logs and events from across an organization's IT infrastructure to provide real-time threat detection and compliance reporting.

  • Aggregates logs from various sources (servers, firewalls, applications).
  • Correlates security events to identify patterns and potential incidents.
  • Provides real-time monitoring and alerting.
  • Aids in compliance reporting and forensic investigations.

Memory trick: SIEM is the 'brain' of security, collecting all the 'eyes and ears' data to spot trouble.

More Network Security questions