nerdexam
CompTIA

CAS-005 · Question #197

A security analyst is reviewing a SIEM and generates the following report: Later, the incident response team notices an attack was executed on the VM001 host. Which of the following should the securit

The correct answer is B. Perform a log correlation on the SIEM solution.. The logs show related events (e.g., malware detection, IPS alert, and eventual connection allowance) from the same source and host. Log correlation connects these related events across time to generate meaningful, actionable alerts. Enhancing correlation would have helped detect

Submitted by stefanr· Mar 6, 2026Security Operations

Question

A security analyst is reviewing a SIEM and generates the following report:

Later, the incident response team notices an attack was executed on the VM001 host. Which of the following should the security analyst do to enhance the alerting process on the SIEM platform?

Exhibits

CAS-005 question #197 exhibit 1
CAS-005 question #197 exhibit 2

Options

  • AInclude the EDR solution on the SIEM as a new log source.
  • BPerform a log correlation on the SIEM solution.
  • CImprove parsing of data on the SIEM.
  • DCreate a new rule set to detect malware.

How the community answered

(55 responses)
  • A
    11% (6)
  • B
    80% (44)
  • C
    2% (1)
  • D
    7% (4)

Explanation

The logs show related events (e.g., malware detection, IPS alert, and eventual connection allowance) from the same source and host. Log correlation connects these related events across time to generate meaningful, actionable alerts. Enhancing correlation would have helped detect the attack pattern earlier.

Community Discussion

No community discussion yet for this question.

Full CAS-005 Practice