300-220 CBRTHD: Conducting Threat Hunting and Defending using Cisco Technologies for Cybersecurity
By Cisco · Question Mode
QuestionQ10
Threat Hunting Techniques
A SOC team must prepare for a new phishing campaign that deceives users into clicking a malicious URL to download a file. When that file runs, it creates a Windows process that harvests user credentials. The team must configure the SIEM tool to generate an alert when a suspicious process is detected.
Which two rules must the team create in the SIEM tool?
Choose two
Community Discussion
No comments yet. Be the first to start the discussion!
Community Discussion