Examlex

Solved

The Analyst Has Created a Correlation Rule to Correlate Events

question 6

Multiple Choice

The analyst has created a correlation rule to correlate events from Anti-Virus (AV) , Network Intrusion Prevention (NIPS) and the firewall. While reviewing just firewall events, the analyst notices a large spike in outbound Command and Control traffic; however, the correlation rule is not triggering. The analyst then looks at the Network IPS and the Anti-Virus views and notices there are no alerts for this traffic. Which of the following features of NIPS and AV are most likely turned off?


Definitions:

Motivated Expert

An individual who possesses a high level of expertise in a specific area and has a strong drive or motivation to apply this expertise towards achieving defined objectives.

Control Subsystem

Part of an organization's management system focused on monitoring and adjusting processes to meet objectives.

Organization's Culture

The shared values, beliefs, norms, and practices that shape the social and psychological environment of a business.

Work Standards

The established expectations and procedures that define how tasks are to be performed in the workplace.

Related Questions