Which tool is commonly used as a SIEM platform for collecting and analyzing security logs?
- A.A. Nmap
- B.B. Splunk
- C.C. Metasploit
- D.D. Wireshark
Why B is correct
Splunk is one of the most popular SIEM platforms, ingesting logs from diverse sources, indexing them for fast search, and providing dashboards, alerts, and analytics. Other popular SIEMs include Microsoft Sentinel, Elastic SIEM, IBM QRadar, and open-source options like Wazuh. SIEMs are central to security operations.
Know someone studying for Security Fundamentals? Send them this one.