CAS-005 · Question #23
A security analyst wants to use lessons learned from a prior incident response to reduce dwell time in the future. The analyst is using the following data points: Which of the following would the…
The correct answer is A. Adjusting the SIEM to alert on attempts to visit phishing sites. The data indicates that admin1 visited a suspicious domain (hacking.com), which triggered an alert. Adjusting the SIEM to alert on attempts to visit phishing sites would allow for faster identification of potentially malicious activity in the future. This approach directly…
Question
A security analyst wants to use lessons learned from a prior incident response to reduce dwell time in the future. The analyst is using the following data points:
Which of the following would the analyst most likely recommend?
Exhibits
Options
- AAdjusting the SIEM to alert on attempts to visit phishing sites
- BAllowing TRACE method traffic to enable better log correlation
- CEnabling alerting on all suspicious administrator behavior
- Dutilizing allow lists on the WAF for all users using GFT methods
How the community answered
(54 responses)- A81% (44)
- B6% (3)
- C9% (5)
- D4% (2)
Explanation
The data indicates that admin1 visited a suspicious domain (hacking.com), which triggered an alert. Adjusting the SIEM to alert on attempts to visit phishing sites would allow for faster identification of potentially malicious activity in the future. This approach directly addresses reducing dwell time by alerting on suspicious or malicious site visits, helping security teams to act
Community Discussion
No community discussion yet for this question.

