QuestionQ73
Security OperationsA security analyst reviews a SIEM and produces the following report:

Later, the incident response team determines that an attack was carried out on the VM001 host. What should the security analyst do to improve the SIEM platform's alerting process?
- A Include the EDR solution on the SIEM as a new log source.
- B Perform a log correlation on the SIEM solution.
- C Improve parsing of data on the SIEM.
- D Create a new rule set to detect malware.
Community Discussion