nerdexam
CompTIA

CS0-003 · Question #136

During a review of SIEM alerts, a security analyst discovers the SIEM is receiving many alerts per day from the file-integrity monitoring toot about files from a newly deployed application that should

The correct answer is C. Check if temporary files are being monitored. The description suggests that many files change many times per day, which is imo typical for temporary files. Additionally "newly deployed application" hints at a possible initial operational misconfiguration.

Submitted by ahmad_uae· Mar 6, 2026Security Operations

Question

During a review of SIEM alerts, a security analyst discovers the SIEM is receiving many alerts per day from the file-integrity monitoring toot about files from a newly deployed application that should not change. Which of the following steps should the analyst complete FIRST to respond to the issue?

Options

  • AWarn the incident response team that the server can be compromised
  • BOpen a ticket informing the development team about the alerts
  • CCheck if temporary files are being monitored
  • DDismiss the alert, as the new application is still being adapted to the environment

How the community answered

(62 responses)
  • A
    16% (10)
  • B
    8% (5)
  • C
    71% (44)
  • D
    5% (3)

Explanation

The description suggests that many files change many times per day, which is imo typical for temporary files. Additionally "newly deployed application" hints at a possible initial operational misconfiguration.

Topics

#SIEM alerts#file integrity monitoring#alert tuning#false positives#security operations

Community Discussion

No community discussion yet for this question.

Full CS0-003 Practice