Solved

A SOC Team Is Informed That a UK-Based User Will

Question 56

Multiple Choice

A SOC team is informed that a UK-based user will be traveling between three countries over the next 60 days. Having the names of the 3 destination countries and the user's working hours, what must the analyst do next to detect an abnormal behavior?


A) Create a rule triggered by 3 failed VPN connection attempts in an 8-hour period
B) Create a rule triggered by 1 successful VPN connection from any nondestination country
C) Create a rule triggered by multiple successful VPN connections from the destination countries
D) Analyze the logs from all countries related to this user during the traveling period

Correct Answer:

verifed

Verified

Unlock this answer now
Get Access to more Verified Answers free of charge

Related Questions