Spring Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

ECCouncil Certified SOC Analyst (CSA v2) 312-39 Question # 28 Topic 3 Discussion

ECCouncil Certified SOC Analyst (CSA v2) 312-39 Question # 28 Topic 3 Discussion

312-39 Exam Topic 3 Question 28 Discussion:
Question #: 28
Topic #: 3

During routine monitoring, the SIEM detects an unusual spike in outbound data transfer from a critical database server. The typical outbound traffic for this server is around 5 MB/hour, but in the past 10 minutes, it has sent over 500 MB to an external IP address. No predefined signatures match this activity, but the SIEM raises an alert due to deviations from the server’s normal behavior profile. Which detection method is responsible for this alert?


A.

Heuristic-based detection


B.

Signature-based detection


C.

Rule-based detection


D.

Anomaly-based detection


Get Premium 312-39 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.