List of questions
Related questions
Question 330 - SY0-601 discussion
An email security vendor recently added a retroactive alert after discovering a phishing email had already been delivered to an inbox. Which of the following would be the best way for the security administrator to address this type of alert in the future?
A.
Utilize a SOAR playbook to remove the phishing message.
B.
Manually remove the phishing emails when alerts arrive.
C.
Delay all emails until the retroactive alerts are received.
D.
Ingest the alerts into a SIEM to correlate with delivered messages.
Your answer:
0 comments
Sorted by
Leave a comment first