easyMultiple Choice
SSCP Practice Question: A small company uses a single firewall at the…
A small company uses a single firewall at the network perimeter. The security team receives alerts from an IDS but cannot correlate them with firewall logs because logs are stored on separate servers with different timestamps. The CEO wants to reduce false positives and improve incident response. What should the security team do first?
⚠ Common exam trap
It's easy for candidates to think a next-generation firewall (NGFW) replaces the need for log correlation, but NGFWs still generate logs that require aggregation and correlation with other sources to reduce false positives and enable effective incident response.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement a SIEM to aggregate and correlate logs from multiple sources.
A SIEM (Security Information and Event Management) system aggregates logs from multiple sources, normalizes timestamps, and correlates events to reduce false positives and improve incident response. This directly addresses the core problem of disparate log sources with unsynchronized timestamps, enabling effective correlation between IDS alerts and firewall logs without replacing existing infrastructure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Increase the IDS sensitivity to catch more threats.
Why it's wrong here
Raising sensitivity generates additional alerts from the same unsynchronised sources, worsening the false-positive volume the CEO wants reduced. Tuning detection is tempting because it addresses alert quality, but correlation requires a common time reference across the IDS and firewall logs, which sensitivity settings do not provide.
- ✗
Replace the IDS with a next-generation firewall.
Why it's wrong here
A next-generation firewall still writes its own logs with its own clock, so the timestamp mismatch with the IDS persists and correlation remains impossible. Consolidating inspection onto one device is tempting, yet the stem's blocker is unsynchronised time sources, which NTP resolves without replacing hardware.
- ✓
Implement a SIEM to aggregate and correlate logs from multiple sources.
Why this is correct
A SIEM aggregates and normalises logs from the firewall and IDS into one platform, applying consistent timestamps so events can be correlated across sources. This directly addresses the separate servers and mismatched timestamps named in the stem, enabling the correlation needed to reduce false positives and speed incident response.
- ✗
Manually align timestamps on each server daily.
Why it's wrong here
Manual daily alignment leaves drift and human error between synchronisation points, so the IDS and firewall events still cannot be reliably correlated in sequence. It is tempting because time synchronisation genuinely underpins log correlation, but that is achieved with NTP across all hosts, not manual adjustment.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.