Courseiva
hardMultiple Select

CS0-003 Practice Question: A SIEM receives endpoint, firewall, identity, and…

A SIEM receives endpoint, firewall, identity, and cloud logs for the same incident, but timestamps do not align across sources. Which actions should the analyst take before finalizing the timeline? (Choose two.)

⚠ Common exam trap

The CS0-004 exam often tests the misconception that you can simply trust the order logs arrive in the SIEM, but the trap is that arrival order does not equal occurrence order due to network latency, buffering, and clock skew.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Verify time synchronization and timezone parsing for each source

Without verifying time synchronization (e.g., NTP configuration) and timezone parsing for each log source, the analyst cannot trust the chronological order of events. A SIEM relies on accurate timestamps to correlate logs from endpoints, firewalls, identity systems, and cloud platforms; misaligned timestamps can lead to incorrect incident reconstruction.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Assume the latest arriving event happened last

    Why it's wrong here

    This assumption is fundamentally flawed in distributed systems and SIEM environments. Network latency, queuing delays, and processing variations across different log sources and collectors mean that events can arrive at the SIEM out of chronological order relative to their actual occurrence time. Relying on ingestion order for incident reconstruction would lead to an inaccurate and potentially misleading timeline of security events, hindering effective analysis and response.

  • ✓

    Verify time synchronization and timezone parsing for each source

    Why this is correct

    Accurate time synchronization, typically via NTP, across all log-generating systems and SIEM components is critical to prevent clock drift, which can cause events to appear out of sequence. Furthermore, correctly parsing and converting timestamps from various sources, which might use different local timezones or formats, ensures that all events are consistently represented against a common temporal baseline. This verification step is essential for building a reliable chronological incident timeline.

  • ✗

    Discard every source except the firewall

    Why it's wrong here

    Discarding valuable telemetry from identity and cloud logs severely cripples a security investigation. A comprehensive understanding of an incident often requires correlating events across multiple domains, such as network activity (firewall), user actions (identity), and cloud resource interactions. Removing these diverse data points eliminates crucial context and visibility, making it impossible to reconstruct the full attack chain or identify lateral movement and privilege escalation, thereby weakening the overall security posture.

  • ✓

    Normalize events to a common timestamp standard such as UTC

    Why this is correct

    Normalizing all event timestamps to a universal standard, such as Coordinated Universal Time (UTC), is imperative for accurate cross-source correlation and incident reconstruction within a SIEM. Even with synchronized clocks, different systems may log in local timezones, leading to discrepancies when comparing events from geographically dispersed sources. Converting all timestamps to UTC provides a single, unambiguous global reference point, enabling precise chronological ordering and correlation of events regardless of their origin.

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.