CAS-005 · Question #197
A security analyst is reviewing a SIEM and generates the following report: Later, the incident response team notices an attack was executed on the VM001 host. Which of the following should the securit
The correct answer is B. Perform a log correlation on the SIEM solution.. The logs show related events (e.g., malware detection, IPS alert, and eventual connection allowance) from the same source and host. Log correlation connects these related events across time to generate meaningful, actionable alerts. Enhancing correlation would have helped detect
Question
A security analyst is reviewing a SIEM and generates the following report:
Later, the incident response team notices an attack was executed on the VM001 host. Which of the following should the security analyst do to enhance the alerting process on the SIEM platform?
Exhibits
Options
- AInclude the EDR solution on the SIEM as a new log source.
- BPerform a log correlation on the SIEM solution.
- CImprove parsing of data on the SIEM.
- DCreate a new rule set to detect malware.
How the community answered
(55 responses)- A11% (6)
- B80% (44)
- C2% (1)
- D7% (4)
Explanation
The logs show related events (e.g., malware detection, IPS alert, and eventual connection allowance) from the same source and host. Log correlation connects these related events across time to generate meaningful, actionable alerts. Enhancing correlation would have helped detect the attack pattern earlier.
Community Discussion
No community discussion yet for this question.

