exam questions

Exam CS0-003 All Questions

View all questions & answers for the CS0-003 exam

Exam CS0-003 topic 1 question 181 discussion

Actual exam question from CompTIA's CS0-003
Question #: 181
Topic #: 1
[All CS0-003 Questions]

While configuring a SIEM for an organization, a security analyst is having difficulty correlating incidents across different systems. Which of the following should be checked first?

  • A. If appropriate logging levels are set
  • B. NTP configuration on each system
  • C. Behavioral correlation settings
  • D. Data normalization rules
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Brick69
Highly Voted 1 year, 2 months ago
Selected Answer: B
From my understanding, it is the same SIEM on different systems. The clocks must be out of sync
upvoted 9 times
...
julessandrin
Highly Voted 1 year, 2 months ago
Selected Answer: B
NTP (Network Time Protocol) needs to be checked
upvoted 5 times
...
cy_analyst
Most Recent 7 months ago
Selected Answer: B
NTP configuration is critical because even if data is normalized, if the timestamps between systems are out of sync, correlation won't work properly. Most SIEM tools rely heavily on accurate timestamps to tie events together, so time synchronization is often checked first.
upvoted 4 times
...
Kmelaun
1 year ago
Selected Answer: B
Time synchronization ensures that computer systems have accurate system time and time-related information by synchronizing the system time with a reference time source, using Network Time Protocol (NTP), an atomic clock, or a global positioning system (GPS). Time synchronization is essential to establish a clear event order.
upvoted 3 times
...
Tdarling77
1 year, 1 month ago
D: Data Normalization rules. Data normalization rules are crucial for SIEM functionality because they translate logs from various systems into a consistent format. This allows the SIEM to recognize and correlate events from different sources that might have different timestamps, log structures, or terminology
upvoted 2 times
...
Franky30
1 year, 1 month ago
Selected Answer: D
NTP stands for Network Time Protocol. It is used to synchronize the clocks of computer systems on a network, ensuring that they all have the correct time. While NTP is important for accurate timestamping of events, it is not typically the first thing to check when having difficulty correlating incidents across different systems in a SIEM. The primary concern in this scenario would be data normalization rules (Option D). Data normalization ensures that logs from different systems are formatted consistently, allowing the SIEM to correlate and analyze them effectively. Checking NTP configuration (Option B) is still important for accurate timestamping, but it usually comes after addressing data normalization issues.
upvoted 4 times
TurboMor
8 months, 1 week ago
Totally agree with this answer and explanation.
upvoted 1 times
...
...
T1bii
1 year, 2 months ago
Might be rather D : different systems = a lot of data variety not well normalized.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago