Câu 94: CAS-005: CompTIA SecurityX
A company's SIEM is designed to associate the company’s asset inventory with user events. Given the following report: Which of the following should a security engineer investigate first as part of a log audit?
Nội dung câu hỏi
A company's SIEM is designed to associate the company’s asset inventory with user events. Given the following report: Which of the following should a security engineer investigate first as part of a log audit?
Các lựa chọn
Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.
- A. An endpoint that is not submitting any logs — đáp án hiện tại
- B. Potential activity indicating an attacker moving laterally in the network
- C. A misconfigured syslog server creating false negatives
- D. Unauthorized usage attempts of the administrator account
Cộng đồng
0 bình luận công khai. Tên thành viên được ẩn một phần.
Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.