CompTIA Server+ SK0-005 Practice Question

Your organization wants its SIEM to raise an alert anytime an account experiences three failed SSH logins within a five-minute window, even if the attempts occur on different Linux servers. Before analysts write the correlation rule, which preparatory action will most reduce the chance of the SIEM missing a distributed brute-force attack because the timestamps in the logs cannot be aligned accurately?

  • Enable weekly rotation of authentication logs to keep log file sizes manageable.

  • Synchronize each server's system clock with a trusted NTP source so all logs share a consistent timestamp baseline.

  • Increase the SSH logging level to VERBOSE on all servers to capture more detail in each failed login entry.

  • Configure circular logging to overwrite the oldest events once the log file reaches a fixed size limit.

CompTIA Server+ SK0-005
Security and Disaster Recovery
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

SAVE $47
$390.00 $343.00
SAVE $53
CompTIA Server+ Voucher with Retake
v5 / SK0-005
Includes Retake
$439.00 $386.00
Bash, the Crucial Exams Chat Bot
AI Bot