QuestionQ303
Procedures and MethodologyAfter a large-scale cyberattack at a financial institution in Chicago, Illinois, investigators are inundated with repeated alerts and duplicate log entries from several monitoring platforms. Before attempting correlation, the team performs a step intended to reduce noise and improve analytical efficiency. What action does this step represent?
- A Format data from different log types into a single log format
- B Compress data, delete repeated entries, or filter similar events
- C Encrypt and authenticate data during collection
- D Gather logs from multiple sources into a centralized system
Community Discussion