🔍

CompTIA Security+ (SY0-701) SY0-701 — Question 23

Topic 1 · Question 23 of 603

Topic 1 · Question 23

A security analyst is reviewing alerts in the SIEM related to potential malicious network traffic coming from an employee’s corporate laptop. The security analyst has determined that additional data about the executable running on the machine is necessary to continue the investigation. Which of the following logs should the analyst use as a data source?

View community discussion →