List of questions
Related questions
Question 322 - CAS-004 discussion
A security analyst is reviewing SIEM events and is uncertain how to handle a particular event. The file is reviewed with the security vendor who is aware that this type of file routinely triggers this alert.
Based on this information, the security analyst acknowledges this alert Which of the following event classifications is MOST likely the reason for this action?
A.
True negative
B.
False negative
C.
False positive
D.
Non-automated response
Your answer:
0 comments
Sorted by
Leave a comment first