300-220 · Question #138
Enhancing a detection methodology could involve:
The correct answer is B. Incorporating user and entity behavior analytics (UEBA). Incorporating User and Entity Behavior Analytics (UEBA) enhances detection methodology by establishing behavioral baselines and flagging anomalies that signature-based tools miss - it adds a dynamic, context-aware layer to threat detection. Option A is wrong because reducing…
Question
Enhancing a detection methodology could involve:
Options
- AReducing the frequency of updates to the threat intelligence database
- BIncorporating user and entity behavior analytics (UEBA)
- CEliminating the review of false positives
- DFocusing exclusively on historical data
How the community answered
(27 responses)- A7% (2)
- B81% (22)
- C4% (1)
- D7% (2)
Explanation
Incorporating User and Entity Behavior Analytics (UEBA) enhances detection methodology by establishing behavioral baselines and flagging anomalies that signature-based tools miss - it adds a dynamic, context-aware layer to threat detection. Option A is wrong because reducing update frequency weakens intelligence coverage, leaving blind spots against emerging threats. Option C is wrong because eliminating false positive review degrades detection quality over time - tuning based on false positives is how detection improves. Option D is wrong because focusing exclusively on historical data ignores zero-day threats and novel attack patterns that have no historical precedent.
Memory tip: Think "UEBA = behavior-aware detection" - the word enhancing implies adding intelligence, not removing steps (A, C) or limiting scope (D). Any answer that removes a process or narrows focus is almost always a distractor when the question asks about enhancement.
Topics
Community Discussion
No community discussion yet for this question.