Big Cyber Monday Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

CompTIA SecurityX Certification Exam CAS-005 Question # 18 Topic 2 Discussion

CompTIA SecurityX Certification Exam CAS-005 Question # 18 Topic 2 Discussion

CAS-005 Exam Topic 2 Question 18 Discussion:
Question #: 18
Topic #: 2

A security engineer receives an alert from the SIEM platform indicating a possible malicious action on the internal network. The engineer generates a report that outputs the logs associated with the incident:

CAS-005 Question 18

Which of the following actions best enables the engineer to investigate further?


A.

Consulting logs from the enterprise password manager


B.

Searching dark web monitoring resources for exposure


C.

Reviewing audit logs from privileged actions


D.

Querying user behavior analytics data


Get Premium CAS-005 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.