An organization is implementing a SIEM platform. Which log source combination should be prioritized for initial ingestion to maximize threat detection capability?
Select an answer to reveal the explanation.
Short Explanation
Here's the deal — b is correct because firewall logs reveal connection attempts and policy violations; AD authentication logs detect credential abuse and lateral movement; DNS logs expose C2 communication and DGA activity; endpoint security logs capture malware activity. These four sources cover the most critical attack vectors for initial SIEM coverage.
Full Explanation
B is correct because firewall logs reveal connection attempts and policy violations; AD authentication logs detect credential abuse and lateral movement; DNS logs expose C2 communication and DGA activity; endpoint security logs capture malware activity. These four sources cover the most critical attack vectors for initial SIEM coverage. A is wrong because physical access logs are useful but not the highest priority for cyber threat detection. C is wrong because printer and HVAC logs have minimal value for detecting cyber attacks. D is wrong because application performance metrics are operational, not security-focused.