Courseiva
Incident Detection Response And Threat PredictionmediumMultiple ChoiceObjective-mapped

CND Practice Question: Incident Detection Response And Threat Prediction

A CND analyst is deploying a centralized Security Information and Event Management (SIEM) solution. To enable proactive threat hunting and rapid incident detection across distributed network segments, what is the primary function of deploying forwarders or agents on endpoints?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

To locally compress, encrypt, and forward normalized log telemetry to the central SIEM collector

SIEM forwarders or agents installed on endpoints collect local event logs (such as Windows Security logs or Linux auditd logs), normalize them, and securely transmit them to the central SIEM collector for correlation, analysis, and alerting without requiring direct remote administrative shares.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • To locally compress, encrypt, and forward normalized log telemetry to the central SIEM collector

    Why this is correct

    SIEM agents collect, parse, and securely stream telemetry and logs from the host operating system to the central SIEM engine.

  • To act as a stateful firewall blocking unauthorized inbound and outbound network packets on the host

    Why it's wrong here

    Host firewalls perform packet filtering; SIEM forwarders are observational and analytical tools.

  • To perform full disk encryption key escrow and manage endpoint certificate lifecycles

    Why it's wrong here

    Disk encryption key management and certificate lifecycles are handled by MDM/EDR or PKI infrastructure, not SIEM forwarders.

  • To automatically execute remediation scripts and isolate compromised endpoints without human intervention

    Why it's wrong here

    Endpoint agents may support automated containment if integrated with an EDR, but standard SIEM forwarders focus on log collection.

About these practice questions

One of 323 original CND practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official EC-Council exam blueprint

This CND practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CND exam.