Question 1
A security architect works with a client on security operations center (SOC) capabilities. The security architect wants to ensure the log correlation and investigation activities are accurate across the infrastructure.
Which of the following is the best for the client to implement?
Accurate time synchronization is essential for reliable log correlation, making Network Time Protocol the best answer. Security investigations routinely combine events from endpoints, servers, authentication infrastructure, firewalls, cloud services, intrusion-detection systems, and other platforms. If those systems maintain inconsistent clocks, the apparent order of events may be incorrect, making it difficult to reconstruct an attack timeline or correlate activity across multiple sources.
NTP is specifically designed to synchronize computer clocks across distributed systems. RFC 5905 defines NTPv4 as a protocol used to synchronize clocks across internet-connected systems. Synchronized timestamps enable the SOC to determine whether events occurring on separate systems actually belong to the same sequence---for example, authentication followed by process execution, lateral movement, and a subsequent network connection.
ZTNA controls access according to Zero Trust principles but does not synchronize timestamps. Account federation addresses identity interoperability. SASE combines network and security services for distributed environments. APIs can integrate tools and exchange information, but integrated data remains difficult to correlate accurately if each system's timestamps are inconsistent.
For forensic and operational analysis, a consistent time reference is therefore foundational to timeline reconstruction, event sequencing, SIEM correlation, and evidentiary accuracy.
Study Guide Reference: Security Operations Logging and Monitoring Time Synchronization NTP SIEM Correlation Timeline Analysis.

