ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 38 - SY0-601 discussion

Report
Export

After a hardware incident, an unplanned emergency maintenance activity was conducted to rectify the issue. Multiple alerts were generated on the SIEM during this period of time. Which of the following BEST explains what happened?

A.
The unexpected traffic correlated against multiple rules, generating multiple alerts.
Answers
A.
The unexpected traffic correlated against multiple rules, generating multiple alerts.
B.
Multiple alerts were generated due to an attack occurring at the same time.
Answers
B.
Multiple alerts were generated due to an attack occurring at the same time.
C.
An error in the correlation rules triggered multiple alerts.
Answers
C.
An error in the correlation rules triggered multiple alerts.
D.
The SIEM was unable to correlate the rules, triggering the alerts.
Answers
D.
The SIEM was unable to correlate the rules, triggering the alerts.
Suggested answer: A

Explanation:

Multiple alerts were generated on the SIEM during the emergency maintenance activity due to unexpected traffic correlated against multiple rules. The SIEM generates alerts when it detects an event that matches a rule in its rulebase. If the event matches multiple rules, the SIEM will generate multiple alerts.

Reference: CompTIA Security+ Study Guide, Exam SY0-601, Chapter 3: Architecture and Design

asked 02/10/2024
laurence peterson
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first