ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 18 - SY0-701 discussion

Report
Export

A security operations center determines that the malicious activity detected on a server is normal. Which of the following activities describes the act of ignoring detected activity in the future?

A.
Tuning
Most voted
Answers (3)
Most voted
A.
Tuning
B.
Aggregating
Answers
B.
Aggregating
C.
Quarantining
Answers
C.
Quarantining
D.
Archiving
Answers
D.
Archiving
Suggested answer: A

Explanation:

Tuning is the activity of adjusting the configuration or parameters of a security tool or system to optimize its performance and reduce false positives or false negatives. Tuning can help to filter out the normal or benign activity that is detected by the security tool or system, and focus on the malicious or anomalous activity that requires further investigation or response. Tuning can also help to improve the efficiency and effectiveness of the security operations center by reducing the workload and alert fatigue of the analysts. Tuning is different from aggregating, which is the activity of collecting and combining data from multiple sources or sensors to provide a comprehensive view of the security posture. Tuning is also different from quarantining, which is the activity of isolating a potentially infected or compromised device or system from the rest of the network to prevent further damage or spread. Tuning is also different from archiving, which is the activity of storing and preserving historical data or records for future reference or compliance. The act of ignoring detected activity in the future that is deemed normal by the security operations center is an example of tuning, as it involves modifying the settings or rules of the security tool or system to exclude the activity from the detection scope. Therefore, this is the best answer among the given options.Reference=Security Alerting and Monitoring Concepts and Tools -- CompTIA Security+ SY0-701: 4.3, video at 7:00;CompTIA Security+ SY0-701 Certification Study Guide, page 191.

asked 02/10/2024
Anand Dillikumar
29 questions
User
Your answer:
3 comments
Sorted by
Up
0
Down
User
Camrin Schroyer

Edited 19 days ago

Voted A

I choose A. Tuning involves adjusting the security systems detection capabilities to reduce false positives by ignoring certain activities that are considered normal and non-threatening.

Reply
Reply
Report

Up
0
Down
User
claudine Nguepnang

Edited 19 days ago

Voted A

Tuning in the context of a Security Operations Center (SOC) refers to the process of adjusting and refining detection rules, thresholds, and alert configurations based on past experiences and analysis.

Reply
Reply
Report

Up
0
Down
User
Charly Ndedi Priso

Edited 19 days ago

Voted A

A correct

Reply
Reply
Report