CISSP Security Operations Practice Question
A security analyst is configuring a SIEM to improve threat detection. Which THREE of the following are essential capabilities of a SIEM system?
⚠ Common exam trap
Candidates often confuse SIEM's passive analysis and reporting role with active remediation tools (vulnerability scanners and patch managers), leading candidates to select options that describe functions SIEMs do not perform themselves.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Reporting and dashboarding
Option C (Reporting and dashboarding) is correct because a SIEM must present security data through dashboards and scheduled or ad hoc reports, giving analysts and compliance teams visibility into trends, incidents, and KPIs derived from correlated events. Option D (Real-time correlation and alerting) is correct because the core value of a SIEM is correlating events from multiple sources against rules, signatures, or behavioral logic and generating timely alerts when suspicious patterns match. Option E (Log aggregation and normalization) is correct because a SIEM must collect logs from disparate devices and applications and normalize them into a common schema (for example, parsing syslog, Windows Event Log, and CEF into consistent fields) so correlation and search can work across sources. Option A (Vulnerability scanning) is not correct because vulnerability assessment is typically performed by dedicated scanners such as Nessus or Qualys, even though their findings may be forwarded to a SIEM. Option B (Automated patch deployment) is not correct because patch management is handled by configuration management or endpoint management tools like WSUS, SCCM, or Intune, not by the SIEM itself.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Vulnerability scanning
Why it's wrong here
Vulnerability scanning is an active process of identifying security weaknesses in systems and applications, typically performed by dedicated vulnerability management tools. While a Security Information and Event Management (SIEM) system can ingest and analyze the output from these scanners to correlate findings with event logs, it does not possess the native functionality to initiate or execute vulnerability scans itself. Its primary role is log analysis and event management, not active system probing.
- ✗
Automated patch deployment
Why it's wrong here
Automated patch deployment falls under the domain of patch management systems or configuration management tools, which are designed to distribute and install software updates and security patches across an organization's endpoints and servers. A SIEM's function is to monitor and alert on security events, including potential indicators of unpatched vulnerabilities or failed patch deployments, but it does not directly manage or execute the patching process. This is an operational task distinct from security monitoring.
- ✓
Reporting and dashboarding
Why this is correct
SIEM systems are fundamentally designed to provide comprehensive reporting and intuitive dashboarding capabilities, which are critical for security analysts to visualize aggregated security data. These features allow for the creation of custom reports on compliance, incident trends, and threat landscapes, alongside real-time dashboards that display key performance indicators and security posture at a glance. This facilitates proactive monitoring, historical analysis, and effective communication of security status to stakeholders.
- ✓
Real-time correlation and alerting
Why this is correct
A core function of a SIEM is its ability to perform real-time correlation of security events from disparate sources, identifying patterns and sequences that indicate potential threats or policy violations. By applying predefined rules and behavioral analytics, the SIEM can detect complex attack methodologies that individual logs might miss, subsequently generating immediate alerts to security analysts for prompt investigation and response. This proactive threat detection is crucial for minimizing incident impact.
- ✓
Log aggregation and normalization
Why this is correct
Log aggregation is the process by which a SIEM collects vast quantities of security logs and event data from numerous sources across an IT environment, including firewalls, servers, applications, and network devices. Following aggregation, normalization transforms these diverse log formats into a common, standardized schema, making the data consistent and machine-readable. This crucial step enables efficient searching, analysis, and correlation of events, regardless of their original source format.
Go deeper
Related to this question
Learn chapter
Cryptography and Its Applications
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Vulnerability
A vulnerability is a weakness in a system, network, or software that could be exploited by a threat to cause harm or unauthorized access.
About these practice questions
One of 816 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.