Cisco 350-201 Exam - Topic 11 Question 120 Discussion
An engineer implemented a SOAR workflow to detect and respond to incorrect login attempts and anomalous user behavior. Since the implementation, the security team has received dozens of false positive alerts and negative feedback from system administrators and privileged users. Several legitimate users were tagged as a threat and their accounts blocked, or credentials reset because of unexpected login times and incorrectlytyped credentials. How should the workflow be improved to resolve these issues?
B) Change the SOAR configuration flow to remove the automatic remediation that is increasing the false positives and triggering threats
A) Meet with privileged users to increase awareness and modify the rules for threat tags and anomalous behavior alerts
D) Increase incorrect login tries and tune anomalous user behavior not to affect privileged accounts
C) Add a confirmation step through which SOAR informs the affected user and asks them to confirm whether they made the attempts
An
2 months agoPansy
2 months agoAshlyn
2 months agoSonia
2 months agoMila
4 months agoLouann
4 months agoValda
4 months agoValentin
4 months agoTyra
5 months agoAliza
5 months agoChau
5 months agoJeffrey
5 months agoGaston
5 months agoMacy
5 months agoTony
6 months agoJade
6 months agoQueen
7 months agoProvidencia
7 months agoBuddy
7 months agoSon
7 months agoJill
7 months agoSharee
7 months agoStephaine
8 months agoOllie
1 month agoTamra
1 month agoFrancisca
2 months ago