List of questions
Related questions
Question 79 - SY0-601 discussion
The SIEM at an organization has detected suspicious traffic coming a workstation in its internal network. An analyst in the SOC the workstation and discovers malware that is associated with a botnet is installed on the device A review of the logs on the workstation reveals that the privileges of the local account were escalated to a local administrator. To which of the following groups should the analyst report this real-world event?
A.
The NOC team
B.
The vulnerability management team
C.
The CIRT
D.
The read team
Your answer:
0 comments
Sorted by
Leave a comment first