ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question

A security team ingests authentication, application, and network intrusion logs into its SIEM but still misses multi-stage attacks in which an external host performs a rapid series of failed logins and, minutes later, successfully runs a high-privilege command on an application server. Which SIEM capability should they implement first to automatically generate a single alert when both conditions occur within a 10-minute window from the same source IP?

  • Enable log normalization so that messages from different devices use a common schema.

  • Extend the SIEM's log retention to one year to ensure historical data is always available.

  • Create a field-based correlation rule that chains failed login events and high-privilege commands from the same source IP within a defined time window.

  • Design a real-time dashboard that displays authentication and intrusion events side by side.

ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Deployment, Operations, Maintenance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot