nerdexam
McAfee

MA0-104 · Question #26

A SIEM can be effectively used to identify active threats from internal systems by monitoring/correlating events that occur

The correct answer is D. in accordance with expected systems use. See the full explanation below for the reasoning.

Question

A SIEM can be effectively used to identify active threats from internal systems by monitoring/correlating events that occur

Options

  • Awhen no one is logged in; for example, after hours or on weekends.
  • Bacross an unusual range of ports or destinations; for example, all high ports.
  • Cirregularly, for example, only on Fridays, or only at end-of-quarter
  • Din accordance with expected systems use.

How the community answered

(66 responses)
  • A
    3% (2)
  • B
    6% (4)
  • C
    12% (8)
  • D
    79% (52)

Community Discussion

No community discussion yet for this question.

Full MA0-104 Practice