Courseiva
Log Management and SIEM →mediumMultiple Choice

GSEC Log Management and SIEM Practice Question

Which THREE of the following represent critical log sources that should be ingested into a SIEM for effective network-wide security visibility? (Choose three)

⚠ Common exam trap

Candidates often include 'physical access logs' or 'printer logs'. While potentially useful, these are not high-priority security telemetry compared to identity, network, and endpoint alerts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Firewall logs

Effective SIEM visibility requires a diverse set of data sources to correlate activities across the infrastructure. Combining endpoint, network, and identity logs allows for comprehensive monitoring. These sources provide the raw telemetry necessary for detecting lateral movement, command-and-control communication, and unauthorized privilege escalation. Without this breadth of information, security teams are likely to miss the early indicators of a sophisticated attack transitioning through different segments of the enterprise network.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Firewall logs

    Why this is correct

    Firewall logs document allowed and denied traffic at network boundaries. They are essential for identifying reconnaissance, data exfiltration, and communication with known malicious command-and-control servers. Analyzing these logs helps security teams understand how traffic flows through the perimeter and identify potential entry points for attackers or internal threats.

  • ✗

    Local printer spooler temporary files

    Why it's wrong here

    Printer spooler files contain transient print job data that is rarely useful for security monitoring. Ingesting these files would consume massive amounts of SIEM storage without providing meaningful security insights, diverting resources away from high-value logs like authentication and network traffic logs that actually detect active security incidents.

  • ✓

    Authentication (Active Directory) logs

    Why this is correct

    Active Directory logs provide a detailed history of user logins, privilege changes, and group membership updates. These are critical for detecting credential theft, account hijacking, and insider threats. Monitoring authentication flows is mandatory for identifying how an attacker establishes a foothold and moves laterally throughout the Windows domain environment.

  • ✓

    Antivirus/EDR alerts

    Why this is correct

    EDR alerts document malicious files, process injections, and suspicious script executions on hosts. These logs are vital for confirming that an attack has successfully bypassed perimeter defenses. Ingesting these alerts into a SIEM provides the context needed to link host-based malicious behavior with network-based communication, enabling complete incident investigation.

  • ✗

    Office document metadata templates

    Why it's wrong here

    Document metadata templates are part of the office suite configuration and do not provide actionable security intelligence regarding system or network activity. Ingesting this non-security data clutters the SIEM database, increases costs, and impedes the ability of analysts to query and find relevant security-related events during an investigation.

About these practice questions

One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.