SY0-701 · Question #1
A security analyst is reviewing alerts in the SIEM related to potential malicious network traffic coming from an employee's corporate laptop. The security analyst has determined that additional data…
The correct answer is D. Endpoint. Endpoint logs are the most suitable data source for gathering additional information about the executable running on the employee's corporate laptop. These logs contain detailed information about processes, executables, and activities occurring on the endpoint, enabling the…
Question
Options
- AApplication
- BIPS/IDS
- CNetwork
- DEndpoint
How the community answered
(20 responses)- A5% (1)
- C5% (1)
- D90% (18)
Explanation
Endpoint logs are the most suitable data source for gathering additional information about the executable running on the employee's corporate laptop. These logs contain detailed information about processes, executables, and activities occurring on the endpoint, enabling the security analyst to understand the behavior of the executable and its potential impact on the system and
Community Discussion
No community discussion yet for this question.