🔍

CompTIA SecurityX (CAS-005) CAS-005 — Question 184

Topic 1 · Question 184 of 393

Topic 1 · Question 184

A security analyst is reviewing a SIEM and generates the following report: Later, the incident response team notices an attack was executed on the VM001 host. Which of the following should the security analyst do to enhance the alerting process on the SIEM platform?

Exhibit 1 for question 184

View community discussion →