exam questions

Exam CS0-003 All Questions

View all questions & answers for the CS0-003 exam

Exam CS0-003 topic 1 question 273 discussion

Actual exam question from CompTIA's CS0-003
Question #: 273
Topic #: 1
[All CS0-003 Questions]

An organization has a critical financial application hosted online that does not allow event logging to send to the corporate SIEM. Which of the following is the best option for the security analyst to configure to improve the efficiency of security operations?

  • A. Configure a new SIEM specific to the management of the hosted environment.
  • B. Subscribe to a threat feed related to the vendor's application.
  • C. Use a vendor-provided API to automate pulling the logs in real time.
  • D. Download and manually import the logs outside of business hours.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
ChopSNap
5 months, 2 weeks ago
Selected Answer: C
C. Use a vendor-provided API to automate pulling the logs in real time. This approach offers several advantages: Real-time monitoring: By pulling logs in real time, the security analyst can immediately detect and respond to threats. Automation: Automating the log collection process reduces manual effort and the risk of human error. Integration with existing SIEM: The collected logs can be integrated with the existing SIEM, allowing for centralized monitoring and analysis.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago