ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 294 - SY0-701 discussion

Report
Export

Which of the following is the first step to take when creating an anomaly detection process?

A.
Selecting events
Answers
A.
Selecting events
B.
Building a baseline
Answers
B.
Building a baseline
C.
Selecting logging options
Answers
C.
Selecting logging options
D.
Creating an event log
Answers
D.
Creating an event log
Suggested answer: B

Explanation:

The first step in creating an anomaly detection process is building a baseline of normal behavior within the system. This baseline serves as a reference point to identify deviations or anomalies that could indicate a security incident. By understanding what normal activity looks like, security teams can more effectively detect and respond to suspicious behavior.

Reference =

CompTIA Security+ SY0-701 Course Content: Domain 04 Security Operations.

CompTIA Security+ SY0-601 Study Guide: Chapter on Monitoring and Baselines.

asked 02/10/2024
mostafa badawi
43 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first