Questions Tagged "SIEM"

Found 10 results for "SIEM"
1. An administrator performs a potentially risky configuration change during an approved maintenance window with a valid change ticket. How should this context affect the investigation?
View Question
2. A user downloads a large number of sensitive files, creates an archive, and then uploads it to an external cloud service. Which combination provides the strongest investigation context?
View Question
3. A user grants a newly registered third-party application permission to read their mailbox. Why should this event be investigated?
View Question
4. An unknown scheduled task creates a PowerShell process every hour on a server. What is the most likely security concern?
View Question
5. Which endpoint event provides the most useful context for determining how a suspicious process was executed?
View Question
6. Which event should generally receive the highest priority during a SOC investigation?
View Question
7. A Conditional Access policy blocks authentication from an unmanaged device. Which event would be most useful to determine whether the policy worked as intended?
View Question
8. An attacker has obtained a user's password but repeatedly fails MFA. Which additional event would be most important for investigation?
View Question
9. Which sign-in event is the strongest indicator of a possible credential-compromise attempt?
View Question
10. Which of the following is the abbreviation of MTBF?
View Question

About This Tag

Showing questions related to the tag "SIEM".

Explore Wikique

Explore practice questions across different categories and subjects.

Browse Categories