Which of the following strategies should an organization use to efficiently manage and analyze multiple types of logs?
Choose an answer
Tap an option to check your answer.
Correct answer: Deploy a SIEM solution.
Why this is the answer
A Security Information and Event Management (SIEM) solution is the most efficient strategy for managing and analyzing multiple types of logs. SIEMs centralize log collection from various sources, normalize the data, and provide real-time correlation and analysis capabilities to detect security incidents and anomalies. This allows for comprehensive visibility and faster response times. Creating custom scripts is inefficient and difficult to maintain for diverse log types and large volumes. Implementing Endpoint Detection and Response (EDR) technology focuses specifically on endpoint activity, not the broad range of logs from network devices, applications, and servers that a SIEM handles. Installing a Unified Threat Management (UTM) appliance provides multiple security functions but primarily focuses on network perimeter security and does not offer the extensive log aggregation and analysis capabilities of a dedicated SIEM.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed