Câu 110: SY0-601: CompTIA Security+ 2021
A security analyst is receiving several alerts per user and is trying to determine if various logins are malicious. The security analyst would like to create a baseline of normal operations and reduce noise. Which of the following actions should the security analyst perform?
Nội dung câu hỏi
A security analyst is receiving several alerts per user and is trying to determine if various logins are malicious. The security analyst would like to create a baseline of normal operations and reduce noise. Which of the following actions should the security analyst perform?
Các lựa chọn
Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.
- A. Adjust the data flow from authentication sources to the SIEM.
- B. Disable email alerting and review the SIEM directly.
- C. Adjust the sensitivity levels of the SIEM correlation engine.
- D. Utilize behavioral analysis to enable the SIEM's learning mode. — đáp án hiện tại
Cộng đồng
0 bình luận công khai. Tên thành viên được ẩn một phần.
Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.