nerdexam
CompTIA

CS0-003 · Question #623

Which of the following explains why a company would consider enriching data before sending it to the SIEM?

The correct answer is C. To provide more information to SOC analysts when analyzing events. Enriching log data adds valuable context - such as user IDs, asset criticality, geolocation, or threat-intel tags - so analysts see a fuller picture immediately, speeding accurate detection and

Submitted by certguy· Mar 6, 2026Security operations

Question

Which of the following explains why a company would consider enriching data before sending it to the SIEM?

Options

  • ATo prevent injection attacks against the log management system
  • BTo reduce the amount and cost of data storage for security incidents
  • CTo provide more information to SOC analysts when analyzing events
  • DTo normalize the data before saving it to the database tables

How the community answered

(45 responses)
  • A
    2% (1)
  • B
    4% (2)
  • C
    91% (41)
  • D
    2% (1)

Explanation

Enriching log data adds valuable context - such as user IDs, asset criticality, geolocation, or threat-intel tags - so analysts see a fuller picture immediately, speeding accurate detection and

Topics

#SIEM#data enrichment#log analysis#threat intelligence

Community Discussion

No community discussion yet for this question.

Full CS0-003 Practice