CompTIA CyberSecurity Analyst CySA+ Certification Exam CS0-003 Question # 126 Topic 13 Discussion

CompTIA CyberSecurity Analyst CySA+ Certification Exam CS0-003 Question # 126 Topic 13 Discussion

CS0-003 Exam Topic 13 Question 126 Discussion:
Question #: 126
Topic #: 13

A security analyst is assisting a software engineer with the development of a custom log collection and alerting tool (SIEM) for a proprietary system. The analyst is concerned that the tool will not detect known attacks and behavioral IoCs. Which of the following should be configured in order to resolve this issue?


A.

Randomly generate and store all possible file hash values.


B.

Create a default rule to alert on any change to the system.


C.

Integrate with an open-source threat intelligence feed.


D.

Manually add known threat signatures into the tool.


Get Premium CS0-003 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.