Thursday, 23 February 2017

McAfee MA0-104 Question Answer

A SIEM can be effectively used to identify active threats from internal systems by monitoring/correlating events that occur.

A. when no one is logged in; for example, after hours or on weekends.
B. across an unusual range of ports or destinations; for example, all high ports.
C. irregularly; for example, only on Fridays, or only at end-of-quarter.
D. in accordance with expected systems use.

Answer: D

No comments:

Post a Comment

Note: only a member of this blog may post a comment.