A SIEM can be effectively used to identify active threats from internal systems by monitoring/correlating events that occur.
A. when no one is logged in; for example, after hours or on weekends.
B. across an unusual range of ports or destinations; for example, all high ports.
C. irregularly; for example, only on Fridays, or only at end-of-quarter.
D. in accordance with expected systems use.
Answer: D
No comments:
Post a Comment
Note: only a member of this blog may post a comment.