View all questions & answers for the PCSAE exam
What is the most effective way to correlate multiple raw events coming from a SIEM and link them together?
Process all alerts by running the respective playbook and link related incidents during post-processing
Ingest all raw events, run a custom script to find the relationship between them and proceed to link them together
Configure a pre-process rule to link related events as they are ingested
Manually go through the incidents created by the raw events and link related incidents
Submit