Câu 21: CA1-005: CompTIA SecurityX
A security engineer receives an alert from the SIEM platform indicating a possible malicious action on the internal network. The engineer generates a report that outputs the logs associated with the incident: Which of the following actions best enables the engineer to investigate further?
Nội dung câu hỏi
A security engineer receives an alert from the SIEM platform indicating a possible malicious action on the internal network. The engineer generates a report that outputs the logs associated with the incident: Which of the following actions best enables the engineer to investigate further?
Các lựa chọn
Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.
- A. Consulting logs from the enterprise password manager
- B. Searching dark web monitoring resources for exposure
- C. Reviewing audit logs from privileged actions
- D. Querying user behavior analytics data — đáp án hiện tại
Cộng đồng
0 bình luận công khai. Tên thành viên được ẩn một phần.
Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.