nerdexam
EC-Council

212-89 · Question #168

Which of the following is a common tool used to help detect malicious internal or compromised actors?

The correct answer is A. User behavior analytics. User Behavior Analytics (UBA) is a cybersecurity process or tool that utilizes machine learning, algorithms, and statistical analyses to detect potentially harmful activities within an organization's network by comparing them against established patterns of users' behavior. It…

Incident Handling and Response Technologies

Question

Which of the following is a common tool used to help detect malicious internal or compromised actors?

Options

  • AUser behavior analytics
  • BSOC2 compliance report
  • CLog forward ng
  • DSyslog configuration

How the community answered

(24 responses)
  • A
    88% (21)
  • B
    4% (1)
  • C
    8% (2)

Explanation

User Behavior Analytics (UBA) is a cybersecurity process or tool that utilizes machine learning, algorithms, and statistical analyses to detect potentially harmful activities within an organization's network by comparing them against established patterns of users' behavior. It is particularly effective in identifying malicious internal actors or compromised users who may be conducting activities that deviate from their normal behavior patterns, such as accessing unauthorized data or systems, excessive file downloads, or unusual login times. UBA tools can flag these activities for further investigation, often before traditional security tools detect a breach. In contrast, SOC2 compliance reports, log forwarding, and syslog configuration are important for maintaining and auditing security standards and for infrastructure monitoring, but they are not primarily focused on detecting malicious behavior based on deviations from established user behavior patterns.

Topics

#user behavior analytics#insider threat detection#threat monitoring#SOC tools

Community Discussion

No community discussion yet for this question.

Full 212-89 Practice