ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 516 - SY0-601 discussion

Report
Export

During an incident, an EDR system detects an increase in the number of encrypted outbound connections from multiple hosts. A firewall is also reporting an increase in outbound connections that use random high ports. An analyst plans to review the correlated logs to find the source of the incident. Which of the following tools will best assist the analyst?

A.
A vulnerability scanner
Answers
A.
A vulnerability scanner
B.
A NGFW
Answers
B.
A NGFW
C.
The Windows Event Viewer
Answers
C.
The Windows Event Viewer
D.
A SIEM
Answers
D.
A SIEM
Suggested answer: D

Explanation:

A security information and event management (SIEM) system will best assist the analyst to review the correlated logs to find the source of the incident. A SIEM system is a type of software or service that collects, analyzes, and correlates logs and events from multiple sources, such as firewalls, EDR systems, servers, or applications. A SIEM system can help to detect and respond to security incidents, provide alerts and reports, support investigations and forensics, and comply with regulations.

Reference: https://www.comptia.org/blog/what-is-a-siem https://www.certblaster.com/wpcontent/ uploads/2020/11/CompTIA-Security-SY0-601-Exam-Objectives-1.0.pdf

asked 02/10/2024
Antonio Carlos Figueiredo Junior
50 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first