Valid Cybersecurity-Architecture-and-Engineering Dumps shared by ExamDiscuss.com for Helping Passing Cybersecurity-Architecture-and-Engineering Exam! ExamDiscuss.com now offer the newest Cybersecurity-Architecture-and-Engineering exam dumps, the ExamDiscuss.com Cybersecurity-Architecture-and-Engineering exam questions have been updated and answers have been corrected get the newest ExamDiscuss.com Cybersecurity-Architecture-and-Engineering dumps with Test Engine here:
An IT organization recently implemented a hybrid cloud deployment. The security team must be able to correlate event data combined from different sources in a central location. What is the best solution?
Correct Answer: D
The correct answer is D - Security information and event management (SIEM). According to WGU Cybersecurity Architecture and Engineering (KFO1 / D488), a SIEM collects and correlates event data from multiple sources (such as cloud and on-premises environments) in real-time. It provides centralized visibility, analysis, and alerting, which is critical in hybrid cloud deployments. File integrity monitoring (A) watches for unauthorized file changes, not event correlation. DLP (B) protects sensitive data but does not correlate events. IDS (C) detects network intrusions but does not combine event data centrally. Reference Extract from Study Guide: "Security information and event management (SIEM) systems collect, normalize, correlate, andanalyze security event data from multiple sources, providing centralized monitoring and alerting." - WGU Cybersecurity Architecture and Engineering (KFO1 / D488), Security Monitoring and Event Management