CertyRush
Đang tải...
C CertyRush
Câu hỏi free preview

Câu 230: SY0-601: CompTIA Security+ 2021

A security analyst in a SOC has been tasked with onboarding a new network into the SIEM. Which of the following BEST describes the information that should feed into a SIEM solution in order to adequately support an investigation?

Nội dung câu hỏi

A security analyst in a SOC has been tasked with onboarding a new network into the SIEM. Which of the following BEST describes the information that should feed into a SIEM solution in order to adequately support an investigation?

Các lựa chọn

Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.

  1. A. Logs from each device type and security layer to provide correlation of events — đáp án hiện tại
  2. B. Only firewall logs since that is where attackers will most likely try to breach the network
  3. C. Email and web-browsing logs because user behavior is often the cause of security breaches
  4. D. NetFlow because it is much more reliable to analyze than syslog and will be exportable from every device

Cộng đồng

0 bình luận công khai. Tên thành viên được ẩn một phần.

Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.

Câu hỏi liền kề