ECCouncil Computer Hacking Forensic Investigator (V9) 312-49v9 Question # 130 Topic 14 Discussion

ECCouncil Computer Hacking Forensic Investigator (V9) 312-49v9 Question # 130 Topic 14 Discussion

312-49v9 Exam Topic 14 Question 130 Discussion:
Question #: 130
Topic #: 14

Which Event Correlation approach assumes and predicts what an attacker can do next after the attack by studying statistics and probability?


A.

Profile/Fingerprint-Based Approach


B.

Bayesian Correlation


C.

Time (Clock Time) or Role-Based Approach


D.

Automated Field Correlation


Get Premium 312-49v9 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.