Study. uk . com
  1. Home
  2. All questions
  3. Question 443

CISSP study material · question 443 of 500

A team wants to find relationships between entries from a firewall and entries from an authentication server. Which function is this, and what is its commonest form?

  1. Event aggregation, most commonly count-based aggregation across sources.
  2. Log conversion, most commonly translation into a common schema.
  3. Event correlation, most commonly rule-based correlation that matches entries against a rule set.
  4. Log reduction, most commonly removal of unrelated entries.
Show the answer

Answer: C. Event correlation, most commonly rule-based correlation that matches entries against a rule set.

Event correlation is finding relationships between two or more log entries, and SP 800-92 says the most common form is rule-based correlation matching multiple entries against rules.

Source: NIST SP 800-92 (NIST) — SP 800-92 > 3.2 Functions

Challenge yourself on this topic → Study as cards