ISC2 CISSP (Certified Information Systems Security Professional)Security OperationsMedium
A financial institution is implementing a new security logging and monitoring strategy. They need to ensure that all critical security events from various systems (firewalls, servers, applications) are collected, correlated, and analyzed in real-time to detect sophisticated threats. Which of the following technologies is BEST suited for this purpose?
- AVulnerability Scanner
- BNetwork Intrusion Detection System (NIDS)
- CData Loss Prevention (DLP) system
- DSecurity Information and Event Management (SIEM)
Show answer & explanationAnswer & explanation
Correct answer: D. Security Information and Event Management (SIEM)
A Security Information and Event Management (SIEM) system is specifically designed to centralize log collection, normalize data, correlate events from disparate sources, and provide real-time analysis and alerting for security incidents, making it ideal for detecting sophisticated threats across an enterprise.
Why the other options are wrong
- A. A vulnerability scanner identifies weaknesses in systems and applications, but it does not perform real-time log collection, correlation, and analysis.
- B. A NIDS primarily monitors network traffic for suspicious patterns; it doesn't aggregate and correlate logs from diverse systems like applications and servers.
- C. A DLP system focuses on preventing sensitive data from leaving the organization, not on real-time correlation of security events from disparate sources.
Security Information and Event Management (SIEM)
A SIEM system provides real-time analysis of security alerts generated by network hardware and applications. It centralizes log management, correlation, and reporting for security events.
- Aggregates logs from various sources.
- Performs real-time correlation and analysis.
- Generates alerts and reports for security incidents.
Memory trick: SIEM is the central brain for all security log data.