CISSP Practice Question: Which tool is BEST suited for centralizing, correlating, and analyzing log data…
Correct Answer: B. Security Information and Event Management (SIEM)
Explanation (CISSP Manager Logic):
A SIEM provides a centralized platform for the collection and correlation of logs from various network devices, servers, and applications. It allows security managers to gain a holistic view of the environment by identifying patterns that individual point solutions might miss.
By implementing a SIEM, you:
- Centralize diverse log sources for easier compliance and auditing.
- Automate the correlation of events to reduce manual analysis time.
- Enable proactive alerting on potential security incidents across the enterprise.
While the other options are relevant, they fall short because:
- A. IPS: Focuses primarily on blocking network-based attacks in real-time rather than centralized log correlation.
- C. NGFW: Acts as a perimeter defense mechanism but does not aggregate logs from other non-network sources.
- D. EDR: Provides deep visibility into host-level activities but lacks the broad infrastructure correlation capabilities of a SIEM.
Think like a manager:
Operational efficiency and visibility are achieved by aggregating data into a single pane of glass to support rapid decision-making and incident response.
Ready to find out if you'd pass?
5,000+ expert-calibrated questions, adaptive CAT mock exams, and gap analysis that shows exactly what to study next.
Try 5 free questions Start 7-day free trial