350-201 Question 125
Single answerAn enterprise security team is struggling to process and analyze data from multiple sources, such as firewalls, intrusion detection systems (IDS), and endpoint security tools. They need to centralize and manage this data to identify threats more effectively and comply with regulatory requirements. Which solution or approach best addresses their needs?
- A
Deploy a Security Information and Event Management (SIEM) system to collect and correlate security data across sources.
- B
Use a standalone log analyzer on each security device to review logs manually.
- C
Implement a Data Loss Prevention (DLP) solution to monitor and protect sensitive information.
- D
Rely on endpoint security tools only, as they provide sufficient visibility into threats.
Show answer and explanation
Correct answer: A
Explanation
A SIEM system is specifically designed for centralizing, managing, and correlating security data from various sources. It enables organizations to streamline threat detection, comply with regulations, and gain better insight into their security posture. Without such a centralized system, managing security events across multiple tools becomes inefficient and prone to oversight.
- A. Correct.
Deploying a SIEM system is the most effective solution for centralizing and correlating security data from multiple sources. It provides real-time analysis, improves visibility, and supports compliance requirements.
- B. Incorrect.
Using a standalone log analyzer on each device is inefficient and does not offer centralized correlation of data. This approach is not scalable for large environments.
- C. Incorrect.
While DLP solutions are important for protecting sensitive data, they do not address the need for centralized security data management and threat correlation.
- D. Incorrect.
Endpoint security tools are valuable for device-level protection but do not provide the centralized data aggregation and correlation required for effective threat identification.