QuestionQ28

Security Engineering

IoCs were missed during a recent security incident due to the reliance on a signature-based detection platform. A security engineer must recommend a solution that can be implemented to address this shortcoming. Which of the following would be the most appropriate recommendation?

Explanation

Signature-based tools can only flag activity that matches a known pattern, so novel or stealthy indicators slip past them. User and Entity Behavior Analytics builds a baseline of normal activity and flags anomalies regardless of whether a matching signature exists, closing exactly this detection gap. File integrity monitoring, secure access service edge, cloud security posture management, and EAP address unrelated concerns such as file changes, network access architecture, cloud configuration compliance, and authentication, respectively.

Community Discussion

No comments yet. Be the first to start the discussion!