CND Practice Question: Incident Detection Response And Threat Prediction
A CND analyst is deploying a centralized Security Information and Event Management (SIEM) solution. To enable proactive threat hunting and rapid incident detection across distributed network segments, what is the primary function of deploying forwarders or agents on endpoints?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To locally compress, encrypt, and forward normalized log telemetry to the central SIEM collector
SIEM forwarders or agents installed on endpoints collect local event logs (such as Windows Security logs or Linux auditd logs), normalize them, and securely transmit them to the central SIEM collector for correlation, analysis, and alerting without requiring direct remote administrative shares.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
To locally compress, encrypt, and forward normalized log telemetry to the central SIEM collector
Why this is correct
SIEM agents collect, parse, and securely stream telemetry and logs from the host operating system to the central SIEM engine.
- ✗
To act as a stateful firewall blocking unauthorized inbound and outbound network packets on the host
Why it's wrong here
Host firewalls perform packet filtering; SIEM forwarders are observational and analytical tools.
- ✗
To perform full disk encryption key escrow and manage endpoint certificate lifecycles
Why it's wrong here
Disk encryption key management and certificate lifecycles are handled by MDM/EDR or PKI infrastructure, not SIEM forwarders.
- ✗
To automatically execute remediation scripts and isolate compromised endpoints without human intervention
Why it's wrong here
Endpoint agents may support automated containment if integrated with an EDR, but standard SIEM forwarders focus on log collection.
About these practice questions
One of 323 original CND practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official EC-Council exam blueprint
This CND practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CND exam.