Câu 34: 350-201: Performing CyberOps Using Core Security Technologies (CBRCOR)
Refer to the exhibit. An engineer configured this SOAR solution workflow to identify account theft threats and privilege escalation, evaluate risk, and respond by resolving the threat. This solution is handling more threats than Security analysts have time to analyze. Without this analysis, the team cannot be proactiv…
Nội dung câu hỏi
Refer to the exhibit. An engineer configured this SOAR solution workflow to identify account theft threats and privilege escalation, evaluate risk, and respond by resolving the threat. This solution is handling more threats than Security analysts have time to analyze. Without this analysis, the team cannot be proactive and anticipate attacks. Which action will accomplish this goal?
Các lựa chọn
Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.
- A. Exclude the step ג€BAN malicious IPג€ to allow analysts to conduct and track the remediation — đáp án hiện tại
- B. Include a step ג€Take a Snapshotג€ to capture the endpoint state to contain the threat for analysis
- C. Exclude the step ג€Check for GeoIP locationג€ to allow analysts to analyze the location and the associated risk based on asset criticality
- D. Include a step ג€Reportingג€ to alert the security department of threats identified by the SOAR reporting engine
Cộng đồng
0 bình luận công khai. Tên thành viên được ẩn một phần.