Câu 230: SY0-601: CompTIA Security+ 2021
A security analyst in a SOC has been tasked with onboarding a new network into the SIEM. Which of the following BEST describes the information that should feed into a SIEM solution in order to adequately support an investigation?
Nội dung câu hỏi
A security analyst in a SOC has been tasked with onboarding a new network into the SIEM. Which of the following BEST describes the information that should feed into a SIEM solution in order to adequately support an investigation?
Các lựa chọn
Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.
- A. Logs from each device type and security layer to provide correlation of events — đáp án hiện tại
- B. Only firewall logs since that is where attackers will most likely try to breach the network
- C. Email and web-browsing logs because user behavior is often the cause of security breaches
- D. NetFlow because it is much more reliable to analyze than syslog and will be exportable from every device
Cộng đồng
0 bình luận công khai. Tên thành viên được ẩn một phần.
Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.