An IT organization recently implemented a hybrid cloud deployment. The security team must be able to correlate event data combined from different sources in a central location.
What is the best solution?
The correct answer is D --- Security information and event management (SIEM).
According to WGU Cybersecurity Architecture and Engineering (KFO1 / D488), a SIEM collects and correlates event data from multiple sources (such as cloud and on-premisesenvironments) in real-time. It provides centralized visibility, analysis, and alerting, which is critical in hybrid cloud deployments.
File integrity monitoring (A) watches for unauthorized file changes, not event correlation. DLP (B) protects sensitive data but does not correlate events. IDS (C) detects network intrusions but does not combine event data centrally.
Reference Extract from Study Guide:
'Security information and event management (SIEM) systems collect, normalize, correlate, andanalyze security event data from multiple sources, providing centralized monitoring and alerting.'
--- WGU Cybersecurity Architecture and Engineering (KFO1 / D488), Security Monitoring and Event Management
=============================================
Katlyn
14 hours agoAimee
6 days agoMirta
11 days agoLouvenia
16 days agoIsabelle
21 days agoGianna
26 days agoElin
1 month agoVerda
1 month agoMakeda
1 month agoLeslee
2 months agoKanisha
2 months agoMary
2 months agoJaney
2 months agoRene
2 months agoGwenn
3 months agoWeldon
3 months agoJacinta
3 months agoCarey
3 months agoCharlie
2 months ago