200-201 · Question #84
Which step in the incident response process researches an attacking host through logs in a SIEM?
The correct answer is A. detection and analysis. During the detection and analysis phase of the incident response process, security analysts utilize various tools and resources, such as SIEM solutions, to detect and investigate potential security incidents or anomalies. They examine logs, alerts, and other collected data within
Question
Which step in the incident response process researches an attacking host through logs in a SIEM?
Options
- Adetection and analysis
- Bpreparation
- Ceradication
- Dcontainment
How the community answered
(46 responses)- A93% (43)
- C2% (1)
- D4% (2)
Explanation
During the detection and analysis phase of the incident response process, security analysts utilize various tools and resources, such as SIEM solutions, to detect and investigate potential security incidents or anomalies. They examine logs, alerts, and other collected data within the SIEM to analyze the behavior of systems and networks. Researching logs in a SIEM helps identify suspicious activities, understand the scope of an attack, and gather information about the attacking host, aiding in the investigation and response to the incident.
Topics
Community Discussion
No community discussion yet for this question.