mediumMultiple Choice
CS0-003 Time synchronization Practice Question
During incident reconstruction, firewall events appear five minutes earlier than endpoint events for the same connection. What should the analyst check first?
⚠ Common exam trap
The CS0-004 exam often tests the misconception that timestamp discrepancies are due to log falsification or that deleting or prioritizing logs is a valid troubleshooting step, when the correct first action is always to verify time synchronization and normalization across all sources.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Time synchronization and timezone normalization across log sources
The five-minute discrepancy between firewall and endpoint events for the same connection is a classic symptom of clock drift or misconfigured time synchronization. The analyst should first check NTP (Network Time Protocol) settings and timezone normalization across all log sources to ensure timestamps are aligned. Without synchronized time, correlation of events during incident reconstruction is unreliable, making this the foundational step in root-cause analysis.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Time synchronization and timezone normalization across log sources
Why this is correct
Clock drift and timezone parsing commonly distort event order in SIEM timelines.
- ✗
Delete one source from the timeline
Why it's wrong here
Removing telemetry reduces evidence quality.
- ✗
Assume the firewall logs are falsified
Why it's wrong here
Time-order issues are often configuration problems, not proof of tampering.
- ✗
Prioritize only the source with the highest EPS
Why it's wrong here
Event volume does not determine chronological accuracy.
Go deeper
Related to this question
Learn chapter
Zeek for Network Traffic Analysis
Key term
Analysis
In incident response, analysis is the process of examining data and events to determine what happened, how it happened, and what actions to take.
Key term
Firewall
A firewall is a network security system that monitors and controls incoming and outgoing traffic based on predetermined security rules to protect trusted internal networks from untrusted external networks.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.