GSEC Log Management and SIEM Practice Question
A security team is implementing a SIEM and needs to ensure that log sources are properly normalized and enriched to support effective correlation and alerting. Which TWO of the following tasks are essential for achieving this goal? (Choose two.)
⚠ Common exam trap
The trap here is thinking that dropping non-conforming logs or storing raw logs indefinitely is part of normalization and enrichment, when those actions actually hinder effective correlation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enriching events with contextual data, such as asset criticality, user identity, and geolocation, from external sources.
Normalization and enrichment are critical for SIEM effectiveness. Mapping fields to a common schema like the Splunk CIM ensures consistent field names for correlation. Enriching with context such as asset criticality and geolocation improves alert accuracy and prioritization. These two tasks together enable the SIEM to correlate events across diverse sources and generate meaningful alerts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enriching events with contextual data, such as asset criticality, user identity, and geolocation, from external sources.
Why this is correct
Enrichment adds context to raw events, enabling more accurate correlation and prioritization. For example, knowing that a server is critical or that a user is a privileged administrator helps analysts assess the severity of an alert. Geolocation can highlight impossible travel. This task is essential for effective alerting because it reduces false positives and helps focus on high-risk activities. It complements normalization by adding business-relevant metadata.
- ✗
Configuring the SIEM to drop logs that do not match the expected format to reduce noise.
Why it's wrong here
Dropping logs that do not match the expected format can lead to loss of critical security events. While it may reduce noise, it also risks discarding logs that could contain indicators of compromise or that require investigation. A better approach is to parse and normalize logs, and if parsing fails, to route them for review. Dropping logs is not an essential task for normalization and enrichment; it can harm visibility.
- ✓
Mapping vendor-specific log fields to a common schema, such as the Splunk Common Information Model (CIM).
Why this is correct
Mapping fields to a common schema like the Splunk CIM is essential for normalization. It allows the SIEM to correlate events from different sources by using consistent field names, such as src_ip or user. Without this, correlation searches would need to handle each vendor's unique field names, which is inefficient and error-prone. This task directly supports effective correlation and alerting across heterogeneous log sources.
- ✗
Storing all raw logs indefinitely in their original format without normalization.
Why it's wrong here
Storing raw logs indefinitely is costly and does not support correlation. Without normalization, the SIEM cannot easily correlate events across sources because field names and formats vary. While retaining raw logs for a period can be useful for forensic deep dives, it is not an essential task for normalization and enrichment. The goal is to make data usable for correlation, which requires normalization and enrichment, not just raw storage.
- ✗
Increasing the SIEM's indexing speed by disabling timestamp recognition on all logs.
Why it's wrong here
Disabling timestamp recognition would break event ordering and correlation, as the SIEM relies on timestamps to sequence events and correlate across sources. It might speed up indexing slightly, but at the cost of accuracy and functionality. Timestamp recognition is fundamental for log management and SIEM operations. This task is not essential for normalization and enrichment; it would undermine them.
About these practice questions
Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.