Câu 9: 312-39V2: Certified SOC Analyst (CSA) v2
A financial institution suspects an insider threat due to unauthorized access attempts on restricted databases. However, the SIEM alerts lack sufficient information to differentiate between legitimate and malicious access. The SOC manager recommends integrating contextual data to improve detection. Which contextual da…
Nội dung câu hỏi
A financial institution suspects an insider threat due to unauthorized access attempts on restricted databases. However, the SIEM alerts lack sufficient information to differentiate between legitimate and malicious access. The SOC manager recommends integrating contextual data to improve detection. Which contextual data source is required to be integrated in this scenario?
Các lựa chọn
Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.
- A. User context from HR systems — đáp án hiện tại
- B. Vulnerability context
- C. Location and physical context from GPS sensors
- D. Threat context from external threat intelligence feeds
Cộng đồng
0 bình luận công khai. Tên thành viên được ẩn một phần.