City VPN concentrators suddenly show bursts of failed logons across many accounts. Which monitoring activities best help the SOC notice and act on that pattern?
Select an answer to reveal the explanation.
Short Explanation
When failed VPN attempts spike, you want all those logs in one bucket and an alert that wakes the SOC—like smoke detectors tied to a central panel. Turning logging off or waiting a year just hides the fire.
Full Explanation
Log aggregation consolidates authentication and other security events so analysts can detect patterns such as credential attacks against municipal VPN gateways. Alerting converts those patterns into actionable notifications for timely response. Disabling logs, delaying review until annual audits, or deleting evidence undermines monitoring effectiveness.