An IT organization recently implemented a hybrid cloud deployment. The security team must be able to correlate event data combined from different sources in a central location.
What is the best solution?
The correct answer is D --- Security information and event management (SIEM).
According to WGU Cybersecurity Architecture and Engineering (KFO1 / D488), a SIEM collects and correlates event data from multiple sources (such as cloud and on-premisesenvironments) in real-time. It provides centralized visibility, analysis, and alerting, which is critical in hybrid cloud deployments.
File integrity monitoring (A) watches for unauthorized file changes, not event correlation. DLP (B) protects sensitive data but does not correlate events. IDS (C) detects network intrusions but does not combine event data centrally.
Reference Extract from Study Guide:
'Security information and event management (SIEM) systems collect, normalize, correlate, andanalyze security event data from multiple sources, providing centralized monitoring and alerting.'
--- WGU Cybersecurity Architecture and Engineering (KFO1 / D488), Security Monitoring and Event Management
=============================================
Doretha
1 month agoAdaline
2 months agoLelia
2 months agoAbel
2 months agoInocencia
2 months agoAnastacia
2 months agoClorinda
2 months agoKatlyn
3 months agoAimee
3 months agoMirta
3 months agoLouvenia
4 months agoIsabelle
4 months agoGianna
4 months agoElin
4 months agoVerda
4 months agoMakeda
4 months agoLeslee
5 months agoKanisha
5 months agoMary
5 months agoJaney
5 months agoRene
5 months agoGwenn
6 months agoWeldon
6 months agoJacinta
6 months agoCarey
6 months agoQuentin
20 days agoBev
25 days agoErinn
1 month agoMacy
1 month agoCharlie
5 months ago