A city's SOC wants better visibility across utility SCADA jump hosts, ERP, and public web apps. What logging approach best supports monitoring and actionable alerting?
Select an answer to reveal the explanation.
Short Explanation
If every log stays in its own drawer, nobody sees the pattern across the city stack. Pipe security-relevant events into a SIEM, keep them long enough, and tune alerts you can act on. Silence, minute-long retention, or siloed disks are how incidents hide.
Full Explanation
SIEM and log management centralize collection, retention, correlation, and alerting so operators can detect and investigate across diverse municipal systems. Retention must meet legal and policy needs, and alerts should be tuned for actionability to reduce noise. Disabling central logging or leaving logs uncorrelated on each host severely weakens security monitoring.