CertyRush
Đang tải...
C CertyRush
Câu hỏi free preview

Câu 12: C1000-018: IBM QRadar SIEM V7.3.2 Fundamental Analysis

An analyst is encountering a large number of false positive results. Legitimate internal network traffic contains valid flows and events which are making it difficult to identify true security incidents. What can the analyst do to reduce these false positive indicators?

Nội dung câu hỏi

An analyst is encountering a large number of false positive results. Legitimate internal network traffic contains valid flows and events which are making it difficult to identify true security incidents. What can the analyst do to reduce these false positive indicators?

Các lựa chọn

Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.

  1. A. Create X-Force rules to detect false positive events.
  2. B. Create an anomaly rule to detect false positives and suppress the event.
  3. C. Filter the network traffic to receive only security related events. — đáp án hiện tại
  4. D. Modify rules and/or Building Block to suppress false positive activity.

Cộng đồng

0 bình luận công khai. Tên thành viên được ẩn một phần.

Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.

Câu hỏi liền kề