CompTIA Security+ (SY0-701)Security OperationsHard

A forensic analyst is correlating login events from a domain controller, a firewall, and a cloud application to build an accurate timeline of an attacker's activity across all three systems. The analyst discovers the timestamps are inconsistent by several minutes across devices. Which underlying configuration issue MOST likely caused this discrepancy?

  1. AThe devices are not synchronized to a common time source
  2. BThe log files were not hashed before collection
  3. CThe SIEM correlation rule threshold was set too high
  4. DThe devices were not included in the same asset inventory
Show answer & explanation

Correct answer: A. The devices are not synchronized to a common time source

Without synchronization to a common, authoritative time source such as NTP, system clocks drift apart, causing timestamp discrepancies that undermine accurate event correlation during forensic timeline reconstruction.

Why the other options are wrong

  • B. Hashing verifies log integrity, not the accuracy of embedded timestamps.
  • C. Correlation rule thresholds affect alert triggering volume, not raw timestamp accuracy.
  • D. Asset inventory membership does not affect a device's internal clock accuracy.

Time Synchronization (NTP) for Log Correlation

The practice of synchronizing all systems to a common authoritative time source (NTP) to ensure consistent, accurate timestamps for log correlation and forensic analysis.

  • Clock drift without NTP can make timelines unreliable during investigations
  • Critical for SIEM correlation across multiple log sources
  • NTP servers typically sync to a stratum hierarchy rooted in atomic/GPS clocks

Memory trick: Every clock must march to the same drumbeat (NTP) or the story falls apart.

More Security Operations questions