Time synchronization – use case

Time is vital for SIEM systems so that events can be placed in chronological order, and for Kerberos as it uses USN and timestamps to prevent replay attacks. In a modern network, the domain controller is synchronized with a time server or the atomic time clock, also known as a reference time source. Stratum has three main types of time servers:

Figure 26: Time synchronization.

From the diagram, you can see that the Stratum 0 time server is the external time server and the internal Stratum 1 time server will synchronize with Stratum 0. A domain controller or SIEM server will synchronize their times with either ...

Get CompTIA Security+ Certification Guide now with O’Reilly online learning.

O’Reilly members experience live online training, plus books, videos, and digital content from 200+ publishers.