CAS-004 Web TestEngine demo

Exit VCEDump CAS-004 CompTIA Advanced Security Practitioner (CASP+)
Question 78 of 100
0% complete
Q78 Single choice

During a review of events, a security analyst notes that several log entries from the FIM system identify

changes to firewall rule sets. While coordinating a response to the FIM entries, the analyst receives alerts from the DLP system that indicate an employee is sending sensitive data to an external email address.

Which of the following would be the most relevant to review in order to gain a better understanding of whether these events are associated with an attack?

Sign in to mark questions

Sign in to save marked questions and return to this demo.

Sign in