An organization wantsbetter network visibility. The organization's requirements include:
* Multivendor/OS-monitoring capabilities
* Real-time collection
* Data correlation
Which of the followingmeets these requirements?
Correct Answer: B
Comprehensive and Detailed Explanation:
ASecurity Information and Event Management (SIEM)systemcollects, correlates, and analyzeslogs from multiple sources in real-time, providingenhanced visibility across multivendor environments.
Breakdown of Options:
* A. SNMP- SNMP is used for networkdevice monitoring, but itlacks real-time correlationacross multiple vendors.
* B. SIEM-Correct answer.SIEMaggregates, analyzes, and correlates logsfrom multiple sources, providingreal-time visibility.
* C. Nmap- Nmap is anetwork scanning toolused for mapping hosts and detecting open ports butdoes not provide log correlation.
* D. Syslog- Syslog collects logs but doesnot correlate or analyzethem in real-time.