Cisco Performing CyberOps Using Core Security Technologies (CBRCOR) 350-201 Question # 14 Topic 2 Discussion

Cisco Performing CyberOps Using Core Security Technologies (CBRCOR) 350-201 Question # 14 Topic 2 Discussion

350-201 Exam Topic 2 Question 14 Discussion:
Question #: 14
Topic #: 2

An employee who often travels abroad logs in from a first-seen country during non-working hours. The SIEM tool generates an alert that the user is forwarding an increased amount of emails to an external mail domain and then logs out. The investigation concludes that the external domain belongs to a competitor. Which two behaviors triggered UEBA? (Choose two.)


A.

domain belongs to a competitor


B.

log in during non-working hours


C.

email forwarding to an external domain


D.

log in from a first-seen country


E.

increased number of sent mails


Get Premium 350-201 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.