Which log source is most valuable to a SIEM?
- A Authentication logs from identity providers and domain controllers
- B Web server access logs only
- C Printer logs
- D Application debug logs
Answer
Authentication logs from identity providers and domain controllers
Most attacks involve credentials at some point, so identity telemetry gives the broadest detection coverage per unit of effort.





