List of questions
Related questions
Question 392 - CAS-004 discussion
During a review of events, a security analyst notes that several log entries from the FIM system identify changes to firewall rule sets. While coordinating a response to the FIM entries, the analyst receives alerts from the DLP system that indicate an employee is sending sensitive data to an external email address. Which of the following would be the most relevant to review in order to gain a better understanding of whether these events are associated with an attack?
A.
Configuration management tool
B.
Intrusion prevention system
C.
Mobile device management platform
D.
Firewall access control list
E.
NetFlow logs
Your answer:
0 comments
Sorted by
Leave a comment first