List of questions
Related questions
Question 429 - CAS-004 discussion
A SOC analyst received an alert about a potential compromise and is reviewing the following SIEM logs:
Which of the following is the most appropriate action for the SOC analyst to recommend?
A.
Disabling account JDoe to prevent further lateral movement
B.
Isolating laptop314 from the network
C.
Alerting JDoe about the potential account compromise
D.
Creating HIPS and NIPS rules to prevent logins
Your answer:
0 comments
Sorted by
Leave a comment first