A security analyst needs to be able to search and correlate logs from multiple sources in a single tool. Which of the following would BEST allow a security analyst to have this ability?
Every single time I've seen the word correlate in questions, the answer has always been SIEM.
From google:
SIEM event correlation is an essential part of any SIEM solution. It aggregates and analyzes log data from across your network applications, systems, and devices, making it possible to discover security threats and malicious patterns of behaviors that otherwise go unnoticed and can lead to compromise or data loss.
A SIEM (Security Information and Event Management) system is designed to collect, store, and analyze log data from various sources in real-time. It allows security analysts to search and correlate logs from multiple sources in a single tool, enabling them to identify and respond to security incidents effectively.
SIEM (Security Information and Event Management) systems are designed to collect, analyze, and correlate log data from various sources such as network devices, servers, applications, and security systems. They provide a centralized platform where logs can be ingested, normalized, and indexed for efficient searching and analysis.
With a SIEM, security analysts can perform log searches, create custom queries, and apply correlation rules to identify patterns, anomalies, and potential security incidents. SIEMs also provide features like real-time monitoring, alerting, and reporting to help analysts detect and respond to security events effectively.
Log collectors are pieces of software that function to gather data from multiple independent sources and feed it into a unified source such as a SIEM. Log collectors only collects the logs. SIEM store all logs
This section is not available anymore. Please use the main Exam Page.SY0-601 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Gravoc
Highly Voted 2 years, 7 months agoFitzd
Highly Voted 2 years, 7 months agoscarceanimal
2 years, 2 months agoProtract8593
Most Recent 1 year, 9 months agoApplebeesWaiter1122
1 year, 10 months agoDALLASCOWBOYS
2 years, 2 months agorhocale
2 years, 4 months agoYebby
2 years, 4 months agoKnowledge33
2 years, 6 months agoRonWonkers
2 years, 7 months ago