McAfee
MA0-104 · Question #26
A SIEM can be effectively used to identify active threats from internal systems by monitoring/correlating events that occur
The correct answer is D. in accordance with expected systems use. See the full explanation below for the reasoning.
Question
A SIEM can be effectively used to identify active threats from internal systems by monitoring/correlating events that occur
Options
- Awhen no one is logged in; for example, after hours or on weekends.
- Bacross an unusual range of ports or destinations; for example, all high ports.
- Cirregularly, for example, only on Fridays, or only at end-of-quarter
- Din accordance with expected systems use.
How the community answered
(66 responses)- A3% (2)
- B6% (4)
- C12% (8)
- D79% (52)
Community Discussion
No community discussion yet for this question.