ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 122 - N10-008 discussion

Report
Export

A network technician needs to correlate security events to analyze a suspected intrusion. Which of the following should the technician use?

A.
SNMP
Answers
A.
SNMP
B.
Log review
Answers
B.
Log review
C.
Vulnerability scanning
Answers
C.
Vulnerability scanning
D.
SIEM
Answers
D.
SIEM
Suggested answer: D

Explanation:

SIEM stands for Security Information and Event Management, which is a tool that collects, analyzes, and correlates data from various network devices and sources to provide alerts and reports on security incidents and events. A network technician can use SIEM to correlate security events to analyze a suspected intrusion, as SIEM can help identify the source, target, method, and impact of an attack, as well as provide recommendations for remediation. Reference:

https://www.comptia.org/blog/what-is-siem

asked 02/10/2024
Kanta Prasad
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first