ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 392 - CAS-004 discussion

Report
Export

During a review of events, a security analyst notes that several log entries from the FIM system identify changes to firewall rule sets. While coordinating a response to the FIM entries, the analyst receives alerts from the DLP system that indicate an employee is sending sensitive data to an external email address. Which of the following would be the most relevant to review in order to gain a better understanding of whether these events are associated with an attack?

A.
Configuration management tool
Answers
A.
Configuration management tool
B.
Intrusion prevention system
Answers
B.
Intrusion prevention system
C.
Mobile device management platform
Answers
C.
Mobile device management platform
D.
Firewall access control list
Answers
D.
Firewall access control list
E.
NetFlow logs
Answers
E.
NetFlow logs
Suggested answer: E

Explanation:

NetFlow logs provide visibility into network traffic patterns and volume, which can be analyzed to detect anomalies, including potential security incidents. They can be invaluable in correlating the timing and nature of network events with security incidents to better understand if there is an association.

asked 02/10/2024
Liam Derwin
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first