QuestionQ44

Security Operations

A security analyst wants to apply lessons learned from a previous incident response to reduce future dwell time. The analyst is using these data points:

Question Image

Which of the following would the analyst be most likely to recommend?

  • A Adjusting the SIEM to alert on attempts to visit phishing sites
  • B Allowing TRACE method traffic to enable better log correlation
  • C Enabling alerting on all suspicious administrator behavior
  • D Utilizing allow lists on the WAF for all users using GET methods
Explanation

Early SIEM alerts for attempts to access phishing sites can reveal likely initial-access activity quickly, enabling investigation and containment before an attacker remains undetected for an extended period.

Community Discussion

No comments yet. Be the first to start the discussion!