An analyst is investigating an anomalous event reported by the SOC. After reviewing the system logs, the analyst identifies an unexpected addition of a user with root-level privileges on the endpoint. Which of the following data sources will BEST help the analyst to determine whether this event constitutes an incident?
A. Patching logs
B. Threat feed
C. Backup logs
D. Change requests Most Voted
E. Data classification matrix
An analyst is investigating an anomalous event reported by the SOC. After reviewing the system logs, the analyst identif
-
answerhappygod
- Site Admin
- Posts: 899604
- Joined: Mon Aug 02, 2021 8:13 am
An analyst is investigating an anomalous event reported by the SOC. After reviewing the system logs, the analyst identif
Join a community of subject matter experts. Register for FREE to view solutions, replies, and use search function. Request answer by replying!