ITPEC FE Subject A October 2024 Question 33
ITPEC FE Subject A October 2024 — Question 33 of 60
SIEM (Security Information and Event Management) — centralized log collection, correlation, and analysis to support incident response.
SIEM does two things: aggregates logs from multiple sources (SIM part) and analyzes events in real time (SEM part).
Why not others:
- (a) Centralized control of network devices + changing configs → NMS (Network Management System)
- (b) Running files in isolated environment + monitoring C&C communication → Sandbox
- (d) Inspecting packet headers + identifying apps + controlling traffic → Firewall / DPI (Deep Packet Inspection)
Key rule: SIEM = collect logs from everywhere → correlate → alert the admin. It analyzes, it does not control or isolate.
AI-generated — may contain errors
The original exam layout is preserved in the image so diagrams, formulas, tables, and code remain accurate.
This question comes from an official ITPEC past paper. ITPEC Practice is an independent study tool and is not affiliated with ITPEC. See the official FE past-paper collection or Report an issue.