CompTIA
CS0-003 · Question #623
Which of the following explains why a company would consider enriching data before sending it to the SIEM?
The correct answer is C. To provide more information to SOC analysts when analyzing events. Enriching log data adds valuable context - such as user IDs, asset criticality, geolocation, or threat-intel tags - so analysts see a fuller picture immediately, speeding accurate detection and
Submitted by certguy· Mar 6, 2026Security operations
Question
Which of the following explains why a company would consider enriching data before sending it to the SIEM?
Options
- ATo prevent injection attacks against the log management system
- BTo reduce the amount and cost of data storage for security incidents
- CTo provide more information to SOC analysts when analyzing events
- DTo normalize the data before saving it to the database tables
How the community answered
(45 responses)- A2% (1)
- B4% (2)
- C91% (41)
- D2% (1)
Explanation
Enriching log data adds valuable context - such as user IDs, asset criticality, geolocation, or threat-intel tags - so analysts see a fuller picture immediately, speeding accurate detection and
Topics
#SIEM#data enrichment#log analysis#threat intelligence
Community Discussion
No community discussion yet for this question.