Câu 24: CS0-002: CompTIA CySA+ Certification Exam (CS0-002)
During a review of SIEM alerts, a security analyst discovers the SIEM is receiving many alerts per day from the file-integrity monitoring tool about files from a newly deployed application that should not change. Which of the following steps should the analyst complete FIRST to respond to the issue?
Nội dung câu hỏi
During a review of SIEM alerts, a security analyst discovers the SIEM is receiving many alerts per day from the file-integrity monitoring tool about files from a newly deployed application that should not change. Which of the following steps should the analyst complete FIRST to respond to the issue?
Các lựa chọn
Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.
- A. Warn the incident response team that the server can be compromised.
- B. Open a ticket informing the development team about the alerts.
- C. Check if temporary files are being monitored. — đáp án hiện tại
- D. Dismiss the alert, as the new application is still being adapted to the environment.
Cộng đồng
0 bình luận công khai. Tên thành viên được ẩn một phần.
Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.