Câu 119: CS0-002: CompTIA CySA+ Certification Exam (CS0-002)
A security analyst at example.com receives SIEM alert for an IDS signature and reviews the associated packet capture and TCP stream:Packet capture: TCP stream: Which of the following actions should the security analyst take NEXT?
Nội dung câu hỏi
A security analyst at example.com receives SIEM alert for an IDS signature and reviews the associated packet capture and TCP stream:Packet capture: TCP stream: Which of the following actions should the security analyst take NEXT?
Các lựa chọn
Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.
- A. Review the known Apache vulnerabilities to determine if a compromise actually occurred.
- B. Contact the application owner for connect.example.local for additional information. — đáp án hiện tại
- C. Mark the alert as a false positive scan coming from an approved source.
- D. Raise a request to the firewall team to block 203.0.113.15.
Cộng đồng
0 bình luận công khai. Tên thành viên được ẩn một phần.
Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.