問題文
An analyst needs to identify the triggering event of a threat that spans several hours of activity. What is the reliable way to do it?
選択肢
- Take the earliest cloud event in the account for that day, since the first recorded operation must be the one that started the situation, so the timeline can be read forward from that point.
- Take the detection with the highest severity, because the situation is always raised by the most severe of its matches and the timestamp of that match is the point at which the investigation should begin.
- Read the timeline of the threat, where the events that make up the situation are laid out in order and the one that raised it is marked as such.
- Compare the account activity against the same period on the previous day and take the first operation that has no counterpart, because the absence of a matching record in the baseline period identifies the point at which behavior departed from normal.