An organization is implementing a SIEM platform. Which log source combination should be prioritized for initial ingestion to maximize threat detection capability?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because firewall logs reveal connection attempts and policy violations; AD authentication logs detect credential abuse and lateral movement; DNS logs expose C2 communication and DGA activity; endpoint security logs capture malware activity. These four sources cover the most critical attack vectors for initial SIEM coverage.
Full explanation below image
Full Explanation
B is correct because firewall logs reveal connection attempts and policy violations; AD authentication logs detect credential abuse and lateral movement; DNS logs expose C2 communication and DGA activity; endpoint security logs capture malware activity. These four sources cover the most critical attack vectors for initial SIEM coverage. A is wrong because physical access logs are useful but not the highest priority for cyber threat detection. C is wrong because printer and HVAC logs have minimal value for detecting cyber attacks. D is wrong because application performance metrics are operational, not security-focused.