ISC2 CISSP (Certified Information Systems Security Professional)Security OperationsMedium

A financial institution is implementing a new security logging and monitoring strategy. They need to ensure that all critical security events from various systems (firewalls, servers, applications) are collected, correlated, and analyzed in real-time to detect sophisticated threats. Which of the following technologies is BEST suited for this purpose?

  1. AVulnerability Scanner
  2. BNetwork Intrusion Detection System (NIDS)
  3. CData Loss Prevention (DLP) system
  4. DSecurity Information and Event Management (SIEM)
Show answer & explanation

Correct answer: D. Security Information and Event Management (SIEM)

A Security Information and Event Management (SIEM) system is specifically designed to centralize log collection, normalize data, correlate events from disparate sources, and provide real-time analysis and alerting for security incidents, making it ideal for detecting sophisticated threats across an enterprise.

Why the other options are wrong

  • A. A vulnerability scanner identifies weaknesses in systems and applications, but it does not perform real-time log collection, correlation, and analysis.
  • B. A NIDS primarily monitors network traffic for suspicious patterns; it doesn't aggregate and correlate logs from diverse systems like applications and servers.
  • C. A DLP system focuses on preventing sensitive data from leaving the organization, not on real-time correlation of security events from disparate sources.

Security Information and Event Management (SIEM)

A SIEM system provides real-time analysis of security alerts generated by network hardware and applications. It centralizes log management, correlation, and reporting for security events.

  • Aggregates logs from various sources.
  • Performs real-time correlation and analysis.
  • Generates alerts and reports for security incidents.

Memory trick: SIEM is the central brain for all security log data.

More Security Operations questions