CertyRush
Đang tải...
C CertyRush
Câu hỏi free preview

Câu 36: 312-39V2: Certified SOC Analyst (CSA) v2

A security team is designing SIEM use-case logic to detect privilege escalation attempts on Windows servers. They have already identified and validated the necessary event sources (e.g., Active Directory logs, Windows Security logs). What should be their next step in the use case logic development process?

Nội dung câu hỏi

A security team is designing SIEM use-case logic to detect privilege escalation attempts on Windows servers. They have already identified and validated the necessary event sources (e.g., Active Directory logs, Windows Security logs). What should be their next step in the use case logic development process?

Các lựa chọn

Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.

  1. A. Define correlation rules and conditions that detect specific privilege escalation patterns — đáp án hiện tại
  2. B. Collect historical security logs to confirm the use case is necessary
  3. C. Implement and test the use case immediately in the production SIEM environment
  4. D. Define response actions for detected incidents before writing the rules

Cộng đồng

0 bình luận công khai. Tên thành viên được ẩn một phần.

Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.

Câu hỏi liền kề