ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 245 - CS0-003 discussion

Report
Export

A cybersecurity analyst is doing triage in a SIEM and notices that the time stamps between the firewall and the host under investigation are off by 43 minutes. Which of the following is the most likely scenario occurring with the time stamps?

A.
The NTP server is not configured on the host.
Answers
A.
The NTP server is not configured on the host.
B.
The cybersecurity analyst is looking at the wrong information.
Answers
B.
The cybersecurity analyst is looking at the wrong information.
C.
The firewall is using UTC time.
Answers
C.
The firewall is using UTC time.
D.
The host with the logs is offline.
Answers
D.
The host with the logs is offline.
Suggested answer: A

Explanation:

The most likely scenario occurring with the time stamps is that the NTP server is not configured on the host. NTP is the Network Time Protocol, which is used to synchronize the clocks of computers over a network. NTP uses a hierarchical system of time sources, where each level is assigned a stratum number. The most accurate time sources, such as atomic clocks or GPS receivers, are at stratum 0, and the devices that synchronize with them are at stratum 1, and so on. NTP clients can query multiple NTP servers and use algorithms to select the best time source and adjust their clocks accordingly1. If the NTP server is not configured on the host, the host will rely on its own hardware clock, which may drift over time and become inaccurate. This can cause discrepancies in the time stamps between the host and other devices on the network, such as the firewall, which may be synchronized with a different NTP server or use a different time zone. This can affect the security analysis and correlation of events, as well as the compliance and auditing of the network23.

Reference: How the Windows Time Service Works, Time Synchronization - All You Need To Know, Firewall rules logging: a closer look at our new network compliance and ...

asked 02/10/2024
miquel martin leiva
32 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first