EC-Council Certified Ethical Hacker (CEH) v12System Hacking Phases and Attack TechniquesMedium
A cybersecurity consultant is advising a small business on improving their security posture. The business has limited resources but wants to ensure they have basic visibility into potential system compromises. The consultant recommends implementing a system that collects and aggregates logs from various operating systems and network devices into a central repository for analysis. Which type of system is the consultant recommending?
- AEndpoint Detection and Response (EDR)
- BSecurity Information and Event Management (SIEM)
- CData Loss Prevention (DLP)
- DIntrusion Prevention System (IPS)
Show answer & explanationAnswer & explanation
Correct answer: B. Security Information and Event Management (SIEM)
A Security Information and Event Management (SIEM) system is designed to collect, aggregate, and analyze log data from various sources across an IT infrastructure. Its primary purpose is to provide centralized visibility and enable detection of security events and potential compromises through correlation and reporting, aligning with the consultant's recommendation.
Why the other options are wrong
- A. EDR focuses on endpoint-level detection and response, not centralized log aggregation from diverse sources.
- C. DLP focuses on preventing sensitive data from leaving the organization, not general log analysis.
- D. IPS focuses on preventing intrusions in real-time, not primarily log aggregation and analysis.
Security Information and Event Management (SIEM)
A security solution that provides real-time analysis of security alerts generated by network hardware and applications, centralizing log management and correlating events to detect threats.
- Aggregates logs from disparate sources.
- Provides centralized visibility and correlation.
- Aids in compliance reporting and incident response.
Memory trick: To 'see everything' and 'manage events', you need a 'SIEM'.