CompTIA SecurityX Certification Exam CAS-005 Question # 66 Topic 7 Discussion

CompTIA SecurityX Certification Exam CAS-005 Question # 66 Topic 7 Discussion

CAS-005 Exam Topic 7 Question 66 Discussion:
Question #: 66
Topic #: 7

A security analyst is reviewing a SIEM and generates the following report:

CAS-005 Question 66

Later, the incident response team notices an attack was executed on the VM001 host. Which of the following should the security analyst do to enhance the alerting process on the SIEM platform?


A.

Include the EDR solution on the SIEM as a new log source.


B.

Perform a log correlation on the SIEM solution.


C.

Improve parsing of data on the SIEM.


D.

Create a new rule set to detect malware.


Get Premium CAS-005 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.