Courseiva
Security Monitoring →mediumMultiple Choice

200-201 Security Monitoring Practice Question

Which component of a SIEM is responsible for converting log data from various sources into a standard format?

⚠ Common exam trap

It's easy for candidates to confuse normalization with aggregation, thinking that simply collecting logs from multiple sources is enough to make them comparable, when in fact normalization is the crucial step that standardizes the data format.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Normalization

Normalization is the SIEM component that parses incoming log data from diverse sources (e.g., syslog, Windows Event Log, NetFlow) and maps the fields into a common, standardized schema. This process ensures that fields like source IP, destination IP, and timestamp are consistently named and formatted, enabling effective correlation and analysis across heterogeneous devices.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Aggregation

    Why it's wrong here

    Aggregation collects and consolidates logs from multiple sources into a central store, but it does not transform their schemas. Normalisation is the component that parses and maps disparate fields into a common format. Aggregation would be correct where the requirement is centralised collection and retention rather than field-level standardisation.

  • ✗

    Alerting

    Why it's wrong here

    Alerting generates notifications when rule or threshold conditions match, consuming normalised and correlated data rather than producing it. Normalisation performs the field mapping into a common schema. Alerting would be correct if the question asked which component notifies analysts once suspicious activity is detected.

  • ✗

    Correlation

    Why it's wrong here

    Correlation links related events across sources to identify patterns or incidents; it operates on already-parsed data and performs no schema conversion. Normalisation is what maps vendor-specific fields into a standard format. Correlation would be the right answer if the question asked how the SIEM detects multi-source attack patterns.

  • ✓

    Normalization

    Why this is correct

    Normalization standardizes log data.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.