PSE-PRISMACLOUD · Question #104
Which type of alert captures unusual user activity and excessive login failures?
The correct answer is A. Anomaly. Anomaly alerts are designed to detect deviations from established baselines, making them the right fit for unusual user behavior and excessive login failures - both patterns that diverge from normal activity. B. Audit Event alerts track specific logged actions (file access…
Question
Which type of alert captures unusual user activity and excessive login failures?
Options
- AAnomaly
- BAudit Event
- CConfiguration
- DNetwork
How the community answered
(56 responses)- A89% (50)
- B2% (1)
- C5% (3)
- D4% (2)
Explanation
Anomaly alerts are designed to detect deviations from established baselines, making them the right fit for unusual user behavior and excessive login failures - both patterns that diverge from normal activity.
- B. Audit Event alerts track specific logged actions (file access, policy changes) for compliance purposes - they record what happened, not whether it's abnormal.
- C. Configuration alerts fire when system settings change unexpectedly, not when user behavior is suspicious.
- D. Network alerts monitor traffic patterns, bandwidth, or connectivity issues - not authentication or user behavior.
Memory tip: Think "A for Abnormal" - Anomaly = something that doesn't match the expected pattern, whether it's a user logging in 50 times or accessing resources at 3am.
Topics
Community Discussion
No community discussion yet for this question.