ISC2 Certified in Cybersecurity (CC)Security OperationsHard

A security operations center (SOC) analyst is reviewing log data from various network devices. They notice a specific sequence of events: an external IP address attempts to connect to a web server, followed by an unsuccessful login attempt, then a port scan of other internal systems, and finally, a successful connection to a different internal server. The analyst correlates these events across multiple log sources to identify the full attack chain. This process is best described as an aspect of:

  1. AVulnerability scanning
  2. BLog aggregation
  3. CPenetration testing
  4. DSecurity information and event management (SIEM)
Show answer & explanation

Correct answer: D. Security information and event management (SIEM)

The correlation of diverse log data from multiple sources (web server, internal systems) to identify a full attack chain and provide actionable intelligence is a primary function of a Security Information and Event Management (SIEM) system.

Why the other options are wrong

  • A. Vulnerability scanning identifies weaknesses, not correlates ongoing attack events.
  • B. Log aggregation is merely collecting logs into one place; a SIEM goes further by correlating and analyzing them.
  • C. Penetration testing is a simulated attack, not the analysis of real-time or historical log data.

SIEM (Security Information and Event Management)

A security solution that provides real-time analysis of security alerts generated by network hardware and applications. SIEMs combine SIM (Security Information Management) and SEM (Security Event Management) functions.

  • Aggregates logs from many sources
  • Correlates events to detect patterns and incidents
  • Provides alerts and reporting for compliance and threat detection

Memory trick: Logs are data, SIEM makes them smart for security.

More Security Operations questions