312-39 Exam Question 46
John as a SOC analyst is worried about the amount of Tor traffic hitting the network. He wants to prepare a dashboard in the SIEM to get a graph to identify the locations from where the TOR traffic is coming.
Which of the following data source will he use to prepare the dashboard?
Which of the following data source will he use to prepare the dashboard?
312-39 Exam Question 47
What does Windows event ID 4740 indicate?
312-39 Exam Question 48
Which of the following attack can be eradicated by converting all non-alphanumeric characters to HTML character entities before displaying the user input in search engines and forums?
312-39 Exam Question 49
Which of the following contains the performance measures, and proper project and time management details?
312-39 Exam Question 50
Charline is working as an L2 SOC Analyst. One day, an L1 SOC Analyst escalated an incident to her for further investigation and confirmation. Charline, after a thorough investigation, confirmed the incident and assigned it with an initial priority.
What would be her next action according to the SOC workflow?
What would be her next action according to the SOC workflow?
