CertyRush
Đang tải...
C CertyRush
Câu hỏi free preview

Câu 21: CA1-005: CompTIA SecurityX

A security engineer receives an alert from the SIEM platform indicating a possible malicious action on the internal network. The engineer generates a report that outputs the logs associated with the incident: Which of the following actions best enables the engineer to investigate further?

Nội dung câu hỏi

A security engineer receives an alert from the SIEM platform indicating a possible malicious action on the internal network. The engineer generates a report that outputs the logs associated with the incident: Which of the following actions best enables the engineer to investigate further?

Minh họa câu hỏi

Các lựa chọn

Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.

  1. A. Consulting logs from the enterprise password manager
  2. B. Searching dark web monitoring resources for exposure
  3. C. Reviewing audit logs from privileged actions
  4. D. Querying user behavior analytics data — đáp án hiện tại

Cộng đồng

0 bình luận công khai. Tên thành viên được ẩn một phần.

Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.

Câu hỏi liền kề