ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 20 - SK0-005 discussion

Report
Export

Which of the following tools will analyze network logs in real time to report on suspicious log events?

A.
Syslog
Answers
A.
Syslog
B.
DLP
Answers
B.
DLP
C.
SIEM
Answers
C.
SIEM
D.
HIPS
Answers
D.
HIPS
Suggested answer: C

Explanation:

SIEM is the tool that will analyze network logs in real time to report on suspicious log events. SIEM stands for Security Information and Event Management, which is a software solution that collects, analyzes, and correlates log data from various sources, such as servers, firewalls, routers, antivirus software, etc. SIEM can detect anomalies, patterns, trends, and threats in the log data and generate alerts or reports for security monitoring and incident response. SIEM can also provide historical analysis and compliance reporting for audit purposes.

Reference:

https://www.manageengine.com/products/eventlog/syslog-server.html

asked 02/10/2024
LEONARDO CESAR MARQUES
44 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first