Which of the following are valid tests that can be applied within a rule in a SIEM system?

Which of the following are valid tests that can be applied within a rule in a SIEM system?
A . Comparing field values against known threat intelligence
B . Testing for the presence of a specific string in log data
C . Checking the velocity of events against a baseline
D . Verifying the digital signature of events

Answer: AB

Subscribe
Notify of
guest
0 Comments
Inline Feedbacks
View all comments