CISSP Practice Question: A financial institution struggles to correlate logs from firewalls, IDS, and servers…
Correct Answer: A. Implement a Security Information and Event Management (SIEM) system to aggregate and correlate logs from across the network.
Explanation (CISSP Manager Logic):
A SIEM provides the centralized visibility necessary to transform disparate data points into actionable intelligence. By automating log aggregation and correlation, management ensures the security team identifies complex attack patterns that are invisible when viewing logs in isolation.
By implementing a SIEM, you:
- Centralize security monitoring to eliminate data silos.
- Enable real-time correlation of events across the entire enterprise.
- Improve incident response times through automated alerting and normalization.
While the other options are relevant, they fall short because:
- B: Increasing logging levels without a correlation tool creates "data fatigue" and overwheles analysts with noise.
- C: Independent dashboards prevent the cross-source analysis required to detect sophisticated, multi-stage threats.
- D: Archiving is a compliance and storage function that does not improve real-time detection capabilities.
Think like a manager:
Prioritize solutions that provide a holistic view of the risk environment. Effective security management relies on the integration of tools to support rapid, informed decision-making.
Ready to find out if you'd pass?
5,000+ expert-calibrated questions, adaptive CAT mock exams, and gap analysis that shows exactly what to study next.
Try 5 free questions Start 7-day free trial