During a post-incident review, the team identifies that detection was delayed because alerts from multiple sources were not correlated. Which improvement would BEST address this issue?
A SIEM ingests logs and alerts from disparate sources into a single platform and applies correlation rules to link related events, such as a failed login followed by a privilege escalation and outbound data transfer, into one incident timeline, directly solving the described correlation gap.
Why this answer
A SIEM solution aggregates logs and alerts from multiple sources, normalizes them, and correlates events across systems to surface related activity that individual tools would miss. This directly addresses the root cause — lack of correlation — by providing centralized detection and alerting. It is the standard architectural answer for improving cross-source detection.
Exam trap
CS0-004 often tests the difference between noise reduction and correlation: candidates pick 'disable non-critical alerts' or 'increase logging' because they sound like detection improvements, but the question specifically targets cross-source correlation, which only a SIEM provides.
How to eliminate wrong answers
Option A is wrong because disabling non-critical alerts reduces noise but does not add correlation; it may even hide signals needed to detect multi-stage attacks. Option C is wrong because adding staff increases response capacity but does not solve the technical problem of uncorrelated alerts across sources. Option D is wrong because increasing logging verbosity produces more data without correlation, likely worsening alert fatigue rather than improving detection.