ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 248 - CS0-003 discussion

Report
Export

While configuring a SIEM for an organization, a security analyst is having difficulty correlating incidents across different systems. Which of the following should be checked first?

A.
If appropriate logging levels are set
Answers
A.
If appropriate logging levels are set
B.
NTP configuration on each system
Answers
B.
NTP configuration on each system
C.
Behavioral correlation settings
Answers
C.
Behavioral correlation settings
D.
Data normalization rules
Answers
D.
Data normalization rules
Suggested answer: B

Explanation:

The NTP configuration on each system should be checked first, as it is essential for ensuring accurate and consistent time stamps across different systems. NTP is the Network Time Protocol, which is used to synchronize the clocks of computers over a network. NTP uses a hierarchical system of time sources, where each level is assigned a stratum number. The most accurate time sources, such as atomic clocks or GPS receivers, are at stratum 0, and the devices that synchronize with them are at stratum 1, and so on. NTP clients can query multiple NTP servers and use algorithms to select the best time source and adjust their clocks accordingly1. If the NTP configuration is not consistent or correct on each system, the time stamps of the logs and events may differ, making it difficult to correlate incidents across different systems. This can affect the security analysis and correlation of events, as well as the compliance and auditing of the network23.

Reference: How the Windows Time Service Works, Time Synchronization - All You Need To Know, What is SIEM? | Microsoft Security

asked 02/10/2024
David Galiata
32 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first