Q9
Single choice
An admin is evaluating entity activity alerts for large internal downloads, excessive host access, accessing hosts with SSH, and host and port scans.
Is this a correct reason for these types of alerts?
(an attacker conducting reconnaissance on the network.)