ISC2 Systems Security Certified Practitioner (SSCP) Practice Question
A security engineer is configuring a next-generation firewall to feed its logs into an on-premises SIEM as part of the organization's continuous monitoring program. The engineer must minimize log loss during bursts of traffic, preserve log integrity in transit, and deliver events to the SIEM in near real time. Which export method BEST meets these requirements?
Send syslog messages via best-effort UDP (port 514) to the SIEM.
Stream logs using syslog over TLS (TCP, port 6514) directly to the SIEM.
Forward logs once per day as encrypted CSV files over SCP.
Use unencrypted syslog over TCP (port 514) without flow control.
TCP-based syslog provides flow-control, so messages are resent until acknowledged, greatly reducing the chance of log loss that is common with best-effort UDP. When the TCP session is wrapped in TLS (commonly over port 6514), the channel is encrypted and includes message-authentication features that protect the integrity and confidentiality of each log record while still streaming events as they occur. In contrast, plain TCP lacks encryption, UDP risks packet loss, and shipping daily files introduces unacceptable latency.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is syslog and why is it important for log management?
Open an interactive chat with Bash
Why is syslog over TLS preferred over unencrypted syslog?
Open an interactive chat with Bash
How does the choice of export method affect log delivery during traffic bursts?
Open an interactive chat with Bash
ISC2 Systems Security Certified Practitioner (SSCP)
Risk Identification, Monitoring and Analysis
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .