Câu 27: SPLK-5003: Splunk Certified Cybersecurity Defense Architect
Kevin is a SOC analyst working with the SRE team to investigate a report of slow responses from a customer-facing web application. While looking at load balancer and WAF logs, Kevin has discovered that one of the web servers hosting the application has gone offline. He does not see any alerts in the WAF or from the en…
Nội dung câu hỏi
Kevin is a SOC analyst working with the SRE team to investigate a report of slow responses from a customer-facing web application. While looking at load balancer and WAF logs, Kevin has discovered that one of the web servers hosting the application has gone offline. He does not see any alerts in the WAF or from the endpoint detection and response agent running on the web server. As part of triaging this incident, what should they do next? (Choose all that apply.)
Các lựa chọn
Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.
- A. Change the WAF from blocking mode to alert-only mode.
- B. Review recently scheduled requests in the company’s change management system that may affect the same server. — đáp án hiện tại
- C. Provision a new server behind the load balancer to return the application to full service.
- D. Review system logs collected from the server to identify who last logged into it. — đáp án hiện tại
Cộng đồng
0 bình luận công khai. Tên thành viên được ẩn một phần.