QuestionQ19

Network security

A network security administrator must implement a solution to:

  • Collect all data from log files in one location.
  • Correlate the data to create alerts.

Which of the following should the administrator implement?

Explanation

A security information and event management (SIEM) system centrally aggregates log data and correlates normalized security events to generate alerts for potential threats. This satisfies both centralized log collection and correlation-based alerting requirements.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!