ISC2 Certified in Cybersecurity (CC)Security OperationsHard
A security operations center (SOC) analyst is reviewing log data from various network devices. They notice a specific sequence of events: an external IP address attempts to connect to a web server, followed by an unsuccessful login attempt, then a port scan of other internal systems, and finally, a successful connection to a different internal server. The analyst correlates these events across multiple log sources to identify the full attack chain. This process is best described as an aspect of:
- AVulnerability scanning
- BLog aggregation
- CPenetration testing
- DSecurity information and event management (SIEM)
Show answer & explanationAnswer & explanation
Correct answer: D. Security information and event management (SIEM)
The correlation of diverse log data from multiple sources (web server, internal systems) to identify a full attack chain and provide actionable intelligence is a primary function of a Security Information and Event Management (SIEM) system.
Why the other options are wrong
- A. Vulnerability scanning identifies weaknesses, not correlates ongoing attack events.
- B. Log aggregation is merely collecting logs into one place; a SIEM goes further by correlating and analyzing them.
- C. Penetration testing is a simulated attack, not the analysis of real-time or historical log data.
SIEM (Security Information and Event Management)
A security solution that provides real-time analysis of security alerts generated by network hardware and applications. SIEMs combine SIM (Security Information Management) and SEM (Security Event Management) functions.
- Aggregates logs from many sources
- Correlates events to detect patterns and incidents
- Provides alerts and reporting for compliance and threat detection
Memory trick: Logs are data, SIEM makes them smart for security.