Security OperationsQuestion 65 of 100
Which system aggregates and correlates log data from many sources to detect security events in near real time?
a.IDS
b.DLP
c.SIEM
d.VPN
Explanation
A security information and event management (SIEM) system centralizes logs from across the environment and correlates them to surface incidents. It supports alerting, dashboards, and investigation. Effective tuning reduces alert fatigue and false positives.
Practice all 100 questions free — no signup required.
Related questions on this topic
- Which is the correct order of the incident response process?
- During incident response, which step focuses on limiting the damage and preventing the threat from spreading?
- Which control monitors network traffic and actively blocks detected malicious activity inline?
- Which technology inspects data in motion and at rest to prevent unauthorized exfiltration of sensitive information?
- Which process applies vendor updates to fix known software vulnerabilities?
- Reducing a system's attack surface by disabling unneeded services and applying secure configurations is called:
Last reviewed: · editorial process
Sen Lin, PrepPass Founder · Verified against CompTIA Security+ (SY0-701) · How we review