CertyRush
Đang tải...
C CertyRush
Câu hỏi free preview

Câu 10: C2150-612: IBM Security QRadar SIEM V7.2.6 Associate Analyst

A Security Analyst found multiple connection attempts from suspicious remote IP addresses to a local host on the DMZ over port 80. After checking related events no successful exploits were detected. Upon checking international documentation, this activity was part of an expected penetration test which requires no imme…

Nội dung câu hỏi

A Security Analyst found multiple connection attempts from suspicious remote IP addresses to a local host on the DMZ over port 80. After checking related events no successful exploits were detected. Upon checking international documentation, this activity was part of an expected penetration test which requires no immediate investigation. How can the Security Analyst ensure results of the penetration test are retained?

Các lựa chọn

Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.

  1. A. Hide the offense and add a note with a reference to the penetration test findings
  2. B. Protect the offense to not allow it to delete automatically after the offense retention period has elapsed — đáp án hiện tại
  3. C. Close the offense and mark the source IP for Follow-Up to check if there are future events from the host
  4. D. Email the Offense Summary to the penetration team so they have the offense id, add a note, and close the Offense

Cộng đồng

0 bình luận công khai. Tên thành viên được ẩn một phần.

Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.

Câu hỏi liền kề