Exam Name: | Certified SOC Analyst (CSA) | ||
Exam Code: | 312-39 Dumps | ||
Vendor: | ECCouncil | Certification: | CSA |
Questions: | 100 Q&A's | Shared By: | herbert |
Which of the following is a set of standard guidelines for ongoing development, enhancement, storage, dissemination and implementation of security standards for account data protection?
John, a threat analyst at GreenTech Solutions, wants to gather information about specific threats against the organization. He started collecting information from various sources, such as humans, social media, chat room, and so on, and created a report that contains malicious activity.
Which of the following types of threat intelligence did he use?
Which of the following are the responsibilities of SIEM Agents?
1.Collecting data received from various devices sending data to SIEM before forwarding it to the central engine.
2.Normalizing data received from various devices sending data to SIEM before forwarding it to the central engine.
3.Co-relating data received from various devices sending data to SIEM before forwarding it to the central engine.
4.Visualizing data received from various devices sending data to SIEM before forwarding it to the central engine.
Where will you find the reputation IP database, if you want to monitor traffic from known bad IP reputation using OSSIM SIEM?