EC-Council
312-39 · Question #19
A security team is designing SIEM use-case logic to detect privilege escalation attempts on Windows servers. They have already identified and validated the necessary event sources (e.g., Active Direct
Sign in or unlock 312-39 to reveal the answer and full explanation for question #19. The question stem and answer options stay visible for context.
Security Incident Detection
Question
A security team is designing SIEM use-case logic to detect privilege escalation attempts on Windows servers. They have already identified and validated the necessary event sources (e.g., Active Directory logs, Windows Security logs). What should be their next step in the use case logic development process?
Options
- ADefine response actions for detected incidents before writing the rules
- BDefine correlation rules and conditions that detect specific privilege escalation patterns
- CImplement and test the use case immediately in the production SIEM environment
- DCollect historical security logs to confirm the use case is necessary
Unlock 312-39 to see the answer
You've previewed enough free 312-39 questions. Unlock 312-39 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.
Topics
#SIEM use case development#correlation rules#privilege escalation detection#use case logic