Symantec
250-513 · Question #179
A DLP administrator needs to forward data loss incidents to the company's Security Information and Event Management (SIEM) system. Which response rule action provides the administrator with the…
The correct answer is B. All: Log to a Syslog Server. See the full explanation below for the reasoning.
Question
A DLP administrator needs to forward data loss incidents to the company's Security Information and Event Management (SIEM) system. Which response rule action provides the administrator with the ability to accomplish this task?
Options
- AAll: Send Email Notification
- BAll: Log to a Syslog Server
- CAll: Add Note
- DAll: Set Attribute
How the community answered
(37 responses)- A3% (1)
- B78% (29)
- C14% (5)
- D5% (2)
Community Discussion
No community discussion yet for this question.