200-201 Exam Question 51

What is a difference between signature-based and behavior-based detection?
  • 200-201 Exam Question 52

    What is a difference between SIEM and SOAR?
  • 200-201 Exam Question 53

    An analyst is investigating an incident in a SOC environment.
    Which method is used to identify a session from a group of logs?
  • 200-201 Exam Question 54

    An offline audit log contains the source IP address of a session suspected to have exploited a vulnerability resulting in system compromise.
    Which kind of evidence is this IP address?
  • 200-201 Exam Question 55

    Which event artifact is used to identify HTTP GET requests for a specific file?