MA0-104 試験問題を無料オンラインアクセス
| 試験コード: | MA0-104 |
| 試験名称: | Intel Security Certified Product Specialist-SIEM |
| 認定資格: | McAfee |
| 無料問題数: | 68 |
| 更新日: | 2026-06-03 |
While investigating beaconing Malware, an analyst can narrow the search quickly by using which of the
following watchlists in the McAfee SIEM?
The analyst has created a correlation rule to correlate events from Anti-Virus (AV>, Network Intrusion
Prevention (NIPS) and the firewall. While reviewing just firewall events, the analyst notices a large spike
in outbound Command and Control traffic, however, the correlation rule is not triggering The analyst then
looks at the Network IPS and the Anti-Virus views and notices there are no alerts for this traffic. Which of
the following features of NIPS and AV are most likely turned off?