会社の最高情報セキュリティ責任者は、会社が提案したクラウドへの移行により、VPC 内のネットワーク トラフィック フロー ログが見えなくなる可能性があることを懸念しています。
この状況で実装するのに最適な代替コントロールは次のうちどれですか?
正解:B
Security information and event management (SIEM) solutions provide near realtime analysis of security alerts generated by a wide variety of network hardware, systems, and applications. SIEM platforms enhance incident detection and response capabilities by providing expanded insights into operational activity through collection, aggregation, and correlation of vast volumes of event data across the entire enterprise environmentSIEM removes much of the need to analyze individual systems by collecting log data and parsing it in a way that makes it easily searched and analyzed regardless of the underlying log format. Additionally, SIEM platforms remove much of the specialized knowledge needed to locate and analyze logs collected and stored on individual systems. For example, a security analyst can learn how to search and query for events using SIEM methods instead of learning how to interact with multiple operating systems, network devices, and/or applications to perform the same task.