Cisco Certified Support Technician (CCST) CybersecurityEndpoint SecurityMedium

A security team is regularly analyzing logs from endpoints to identify unusual patterns, unauthorized access attempts, or potential compromises. They are particularly interested in correlating events across multiple systems to detect a coordinated attack. Which endpoint security concept does this activity best represent?

  1. AMobile Application Management (MAM)
  2. BSecure Configuration Baseline
  3. CVulnerability Scanning
  4. DSecurity Information and Event Management (SIEM)
Show answer & explanation

Correct answer: D. Security Information and Event Management (SIEM)

Security Information and Event Management (SIEM) systems collect, aggregate, and analyze log data from various sources, including endpoints, to identify security incidents and correlate events across multiple systems for a holistic view of potential threats.

Why the other options are wrong

  • A. MAM manages applications on mobile devices, unrelated to endpoint log analysis.
  • B. A secure configuration baseline defines standard settings, not the analysis of real-time logs for attacks.
  • C. Vulnerability scanning identifies weaknesses but doesn't analyze ongoing log data for attacks.

Security Information and Event Management (SIEM)

A security system that centralizes the collection, storage, and analysis of security logs and events from various sources to provide real-time threat detection and incident response capabilities.

  • Aggregates logs from multiple systems.
  • Uses correlation rules to identify security incidents.
  • Provides a centralized view of security posture.

Memory trick: SIEM is the 'security detective' connecting all the clues.

More Endpoint Security questions