大規模企業内で発生したデータ侵害の疑いを受け、調査担当者が膨大なネットワークログの分析を任されました。このタスクには、複数のネットワークデバイスからログを収集・管理するだけでなく、リアルタイムのアラート管理、メタデータ分析、異常なトラフィックパターンの明確な表示を可能にするツールが必要です。調査担当者は、ログを整理し、ネットワークイベントを関連付けて攻撃の全容を把握するための最も効果的なソリューションを特定する必要があります。このタスクに最も適したツールは次のうちどれでしょうか?
正解:A
Option A. Security Onion is the best answer because the question requires a solution for collecting and managing logs from multiple devices , supporting real-time alerting , enabling metadata analysis , and helping investigators correlate events across the environment. CHFI v11 explicitly includes centralized logging using SIEM solutions , SIEM solutions , types of event correlation , event correlation approaches , and incident detection and examination with SIEM tools .
Security Onion fits that need because it is built around enterprise-scale monitoring, alerting, and network visibility. It is far more suitable than the other options for incident-centric log aggregation and correlation.
OSFClone is a bootable acquisition utility, not a log-correlation platform. Intella Pro is oriented toward eDiscovery and evidence review rather than network event monitoring. Tableau is commonly associated with write-blocking hardware, not SIEM-style network analysis.
Because the task is to organize logs, examine anomalous traffic patterns, and correlate network events to understand the attack timeline and scope, the most CHFI-aligned choice is Security Onion . It best matches the blueprint's network-forensics and SIEM-focused objectives.