Which of the following describes a security alerting and monitoring tool that collects system, application, and network logs from multiple sources in a centralized system?
Choose an answer
Tap an option to check your answer.
Correct answer: SIEM.
Why this is the answer
A Security Information and Event Management (SIEM) system is designed to collect, aggregate, and analyze log data from various sources across an organization's IT infrastructure. This centralized approach allows SIEMs to identify and alert on security threats, policy violations, and anomalous activities that might otherwise go unnoticed. Data Loss Prevention (DLP) focuses on preventing sensitive data from leaving the organization. An Intrusion Detection System (IDS) monitors network or system activities for malicious activity or policy violations and alerts on them, but typically doesn't offer the comprehensive log aggregation and analysis of a SIEM. Simple Network Management Protocol (SNMP) is used for managing network devices and collecting basic operational data, not for centralized security log analysis.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed