SSCP • Practice Exam 58
Free SSCP practice exam — 20 questions with explanations. Set 58. No signup required.
A security administrator is building a Security Information and Event Management (SIEM) correlation rule to detect a specific attack pattern on a Linux web server. The rule must identify attempts where an attacker sends a single malicious HTTP request that causes the server to execute an arbitrary operating system command. Which of the following event sources would provide the most reliable and immediate evidence for this rule?
Choose an answer to begin — your selection is scored in the full session.
20 questions · instant feedback and full explanations after every question.