N10-009 exam dumps

N10-009 practice question 211 of 329

Network+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

N10-009 Question 211

Single answerLog aggregation: Syslog collector, Security information and event management (SIEM)

A network administrator is deploying centralized logging for routers, switches, Linux servers, and a firewall. Management wants one system to receive standard syslog messages from the devices and also automatically correlate events, trigger alerts for suspicious patterns, and support incident investigations with searchable dashboards. Which solution best meets these requirements?

  1. A

    Configure all devices to send logs to a SIEM platform

  2. B

    Configure all devices to send logs only to a standalone syslog collector

  3. C

    Enable SNMP traps on all devices instead of log forwarding

  4. D

    Send logs to a TFTP server for centralized review

Show answer and explanation

Correct answer: A

Explanation

The best answer is to send logs to a SIEM platform. A syslog collector focuses on receiving and storing syslog messages from devices that support syslog. A SIEM goes further by aggregating logs from multiple sources, normalizing data, correlating events, generating alerts, and supporting investigation through queries and dashboards. In a real deployment, routers, switches, firewalls, and Linux servers often forward syslog to a SIEM directly or through collectors. This aligns with common best practices from vendors and industry guidance: use syslog for standardized log transport from supported devices, and use a SIEM when the organization needs security monitoring, correlation, and incident response support rather than simple centralized log storage.

  • A. Correct.

    Correct. A SIEM can ingest syslog from network devices and servers while also providing correlation, alerting, dashboards, and investigation features. This directly matches the requirement for centralized collection plus security analytics. In practice, many SIEM deployments use syslog as one of the ingestion methods, then normalize and correlate events across multiple sources.

  • B. Incorrect.

    Incorrect. A standalone syslog collector is useful for centralizing and storing syslog messages, but by itself it typically does not provide the broader security analytics expected from a SIEM, such as event correlation across sources, alerting on suspicious patterns, and investigation-oriented dashboards. This option addresses aggregation but not the full management requirement.

  • C. Incorrect.

    Incorrect. SNMP traps can send event notifications from devices, but they are not a replacement for centralized log aggregation and do not provide the detailed log records and security analytics described in the scenario. A candidate might choose this because traps are also used for monitoring alerts, but they are not designed to serve as a full logging and investigation platform.

  • D. Incorrect.

    Incorrect. TFTP is a simple file transfer protocol commonly used for device configuration or image transfer, not for centralized log collection and security event analysis. This is a plausible distractor because administrators may already use TFTP in network operations, but it does not meet the requirement for real-time log ingestion, correlation, and alerting.

Timed practice exam

Take a N10-009 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam