View all questions & answers for the Implementing and Operating Cisco Security Core Technologies v1.1 (350-701 SCOR v1.1) Exam Materials exam
Implementing and Operating Cisco Security Core Technologies v1.1 (350-701 SCOR v1.1) Exam Materials-Question 476 Discussion
Comments
Selected Answers: A
interesting file access (Option B): This engine does not baseline user identity deviations. Instead, it is configured by an administrator to watch a specific list of highly sensitive or critical files (e.g., system configuration or password files) and flags an alert whenever any process or entity touches them.
Which suspicious pattern enables the Cisco Secure Workload platform to detect deviations in the normal behavior of users? (Choose one answer)
Brave-Dump Clients Votes