Courseiva

GCIH Network and Log Investigations Practice Question

Which of the following is a primary benefit of using a centralized log management (CLM) solution during an incident?

⚠ Common exam trap

Candidates often select answers focused purely on local storage capacity or simple backup solutions, forgetting that incident correlation requires unified multi-source visibility.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It provides a unified view for log correlation.

Centralized log management aggregates logs from disparate sources, providing a single point of visibility. This is crucial for correlation, as it allows analysts to link events across different systems—such as matching a firewall block with a specific endpoint execution. Without CLM, responders must manually query every host, which is slow, error-prone, and often impossible if an attacker deletes local logs to cover their tracks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It automatically blocks all malicious traffic.

    Why it's wrong here

    Log management systems are primarily passive; they collect, index, and analyze logs. They are not firewalls or IPS devices, so they do not inherently block traffic. Incident response requires the human analyst to take action based on the insights provided by the logs in the system.

  • ✓

    It provides a unified view for log correlation.

    Why this is correct

    The main benefit of a CLM solution is its ability to aggregate logs from multiple devices into one searchable interface. This enables analysts to correlate activities, such as matching a network login on a server with an unusual process start on an endpoint, which is essential for investigation.

  • ✗

    It encrypts all data on the network.

    Why it's wrong here

    Log management systems manage logs, not network traffic encryption. They may use encryption to protect the logs they store, but they do not provide general-purpose network encryption for the infrastructure. Providing data encryption is the responsibility of VPNs, TLS, and other network-level security technologies.

  • ✗

    It prevents unauthorized local access.

    Why it's wrong here

    Centralized log management does not provide access control or prevent local access to systems. It is an auditing and analysis tool. Access control is managed through identity and access management systems, while log systems exist to provide accountability after the fact, not to enforce access security.

About these practice questions

One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.