A Security Information and Event Management (SIEM) system collects, correlates, and analyzes logs from multiple sources in real-time, providing enhanced visibility across multivendor environments.
Breakdown of Options:
A. SNMP – SNMP is used for network device monitoring, but it lacks real-time correlation across multiple vendors.
B. SIEM – Correct answer. SIEM aggregates, analyzes, and correlates logs from multiple sources, providing real-time visibility.
C. Nmap – Nmap is a network scanning tool used for mapping hosts and detecting open ports but does not provide log correlation.
D. Syslog – Syslog collects logs but does not correlate or analyze them in real-time.
[Reference:, CompTIA Network+ (N10-009) Official Study Guide – Domain 3.3: Explain network security concepts., NIST Special Publication 800-92: Guide to Computer Security Log Management, , , , , ]
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit