List of questions
Related questions
Question 52 - SY0-701 discussion
A security analyst is reviewing alerts in the SIEM related to potential malicious network traffic coming from an employee's corporate laptop. The security analyst has determined that additional data about the executable running on the machine is necessary to continue the investigation. Which of the following logs should the analyst use as a data source?
A.
Application
B.
IPS/IDS
C.
Network
D.
Endpoint
Your answer:
0 comments
Sorted by
Leave a comment first