View all questions & answers for the NSE 7 - Security Operations 7.6 Architect Materials exam
Question 57 Discussion
Comments
Selected Answers: B, C, D
View all questions & answers for the NSE 7 - Security Operations 7.6 Architect Materials exam
Selected Answers: B, C, D
You want to trigger an incident when multiple failed logins from the same host are followed by a successful login on that same host within 15 minutes. The rule must correlate all events by source IP address and user to ensure they belong to the same login sequence. Which three configurations achieve this goal? (Choose three answers)
Brave-Dump Clients Votes