easyMultiple ChoiceObjective-mapped
CISSP Practice Question: A security analyst is conducting a review of…
A security analyst is conducting a review of aggregated logs from firewalls, IDS, and servers to detect anomalous behavior. This activity is best described as:
⚠ Common exam trap
Many candidates confuse security log analysis (a passive, detective control) with vulnerability scanning or penetration testing (active, preventive controls), leading candidates to choose a more 'technical-sounding' option like vulnerability scanning.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Security log analysis
Security log analysis involves the systematic review of logs from firewalls, IDS, and servers to identify patterns, anomalies, or indicators of compromise. This activity directly matches the scenario of detecting anomalous behavior through aggregated log review, which is a core practice in security monitoring and incident detection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Security log analysis
Why this is correct
Security log analysis is the systematic examination of aggregated log data from various sources to identify security incidents, anomalies, and policy violations. This process involves reviewing event records, often correlated and normalized, to detect patterns indicative of malicious activity, system failures, or unauthorized access attempts. By analyzing these operational records, a security analyst can gain critical insights into the security posture and operational health of the environment, directly addressing the task of reviewing aggregated logs.
- ✗
Risk assessment
Why it's wrong here
Risk assessment is a comprehensive process that identifies, analyzes, and evaluates potential security risks to an organization's assets. It involves determining the likelihood of threats exploiting vulnerabilities and the potential impact of such events, leading to a prioritized list of risks. This strategic activity focuses on understanding potential future harm and informing risk mitigation strategies, rather than the tactical review of historical operational data found in aggregated logs for current or past incidents.
- ✗
Vulnerability scanning
Why it's wrong here
Vulnerability scanning is an automated process designed to identify known security weaknesses and misconfigurations within systems, applications, and networks. It involves using specialized tools to probe targets for common vulnerabilities, comparing system responses against a database of known flaws. While crucial for proactive security, this technique focuses on discovering potential entry points for attackers and does not involve the analysis of operational logs to detect actual security events or anomalies that have already occurred.
- ✗
Penetration testing
Why it's wrong here
Penetration testing is a simulated cyberattack conducted by ethical hackers to proactively identify and exploit security vulnerabilities in a controlled environment. This active, hands-on methodology aims to demonstrate the feasibility of an attack, assess the effectiveness of existing security controls, and uncover weaknesses that automated tools might miss. Unlike log analysis, which is a passive review of system-generated data, penetration testing involves actively attempting to breach security perimeters and systems.
Go deeper
Related to this question
Learn chapter
Security Governance and Principles
Key term
IDS
An IDS is a security system that monitors network or system traffic for suspicious activity and alerts administrators to potential threats, but does not actively block them.
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
About these practice questions
Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.