200-201 Exam Question 51
What is a difference between signature-based and behavior-based detection?
200-201 Exam Question 52
What is a difference between SIEM and SOAR?
200-201 Exam Question 53
An analyst is investigating an incident in a SOC environment.
Which method is used to identify a session from a group of logs?
Which method is used to identify a session from a group of logs?
200-201 Exam Question 54
An offline audit log contains the source IP address of a session suspected to have exploited a vulnerability resulting in system compromise.
Which kind of evidence is this IP address?
Which kind of evidence is this IP address?
200-201 Exam Question 55
Which event artifact is used to identify HTTP GET requests for a specific file?
