QuestionQ76

Cortex XSIAM

Which tool is the most operationally efficient for detecting events involving abuse of authorized access and malicious insider activity across endpoints, networks, identity, and the cloud?

  • A Honeypots or decoy servers
  • B Correlation rules
  • C Network traffic analysis
  • D User and Entity Behavior Analytics (UEBA)
Explanation

User and Entity Behavior Analytics (UEBA) baselines normal user and entity activity and identifies anomalous behavior associated with credential misuse and insider threats across diverse data sources, including endpoint, network, identity, and cloud telemetry.

Community Discussion

No comments yet. Be the first to start the discussion!