McAfee
MA0-104 · Question #26
MA0-104 Question #26: Real Exam Question with Answer & Explanation
Sign in or unlock MA0-104 to reveal the answer and full explanation for question #26. The question stem and answer options stay visible for context.
Question
A SIEM can be effectively used to identify active threats from internal systems by monitoring/correlating events that occur
Options
- Awhen no one is logged in; for example, after hours or on weekends.
- Bacross an unusual range of ports or destinations; for example, all high ports.
- Cirregularly, for example, only on Fridays, or only at end-of-quarter
- Din accordance with expected systems use.
Unlock MA0-104 to see the answer
You've previewed enough free MA0-104 questions. Unlock MA0-104 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.