ExamGecko
Question list
Search
Search

List of questions

Search

Question 41 - PCCSE discussion

Report
Export

The Unusual protocol activity (Internal) network anomaly is generating too many alerts. An administrator has been asked to tune it to the option that will generate the least number of events without disabling it entirely.

Which strategy should the administrator use to achieve this goal?

A.
Disable the policy
Answers
A.
Disable the policy
B.
Set the Alert Disposition to Conservative
Answers
B.
Set the Alert Disposition to Conservative
C.
Change the Training Threshold to Low
Answers
C.
Change the Training Threshold to Low
D.
Set Alert Disposition to Aggressive
Answers
D.
Set Alert Disposition to Aggressive
Suggested answer: B

Explanation:

To reduce the number of alerts generated by the 'Unusual protocol activity (Internal)' network anomaly without entirely disabling the policy, setting the Alert Disposition to Conservative (option B) is the most effective strategy. This configuration adjusts the sensitivity of the anomaly detection, reducing the likelihood of false positives and minimizing alert fatigue without compromising the ability to detect genuine security threats. By adopting a more conservative approach to anomaly detection, the administrator can ensure that only the most significant and potentially harmful activities trigger alerts, thus maintaining a balance between security vigilance and operational efficiency.

asked 23/09/2024
Med Amine Aloui
26 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first