Which of the following should be used to aggregate log data in order to create alerts and detect anomalous activity?
Choose an answer
Tap an option to check your answer.
Correct answer: SIEM.
Why this is the answer
A Security Information and Event Management (SIEM) system is designed to aggregate and analyze log data from various sources across an organization's IT infrastructure. This aggregation allows the SIEM to correlate events, identify patterns, generate alerts for suspicious activities, and detect anomalies that might indicate a security breach or policy violation. A Web Application Firewall (WAF) protects web applications from common attacks but doesn't aggregate logs from the entire infrastructure. Network taps are hardware devices used to monitor network traffic, not to aggregate and analyze logs. An Intrusion Detection System (IDS) monitors network or system activities for malicious behavior and can generate alerts, but a SIEM provides a more comprehensive, centralized log aggregation and analysis platform.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed