Skip to content
CS0-003
Reporting and Communication
medium
Question 8 of 16

During a post-incident review, the team identifies that the initial detection time was significantly longer than expected due to missing log sources in the SIEM. How should this finding be addressed in the lessons learned report?

ADocument the detection gap as a finding with a specific action plan to onboard the missing log sources
BClose the review without changes since the incident was resolved
CAttribute the failure to the SIEM vendor and file a support ticket
DRemove the affected systems from future monitoring scope

Educational Content — CertQnA practice questions are written against official exam objectives, covering the same domains tested on the real exam. All content is original and independent — not actual exam questions, not affiliated with any certification vendor. Learn more about our content policy

Discussion

Be the first to share your understanding of this concept

⚠️ Discussion is for concept clarification only. Do not share or request actual exam questions or answers.

Sign in to join the discussion