Courseiva

CS0-004

Study mode — explanations shown

1

Security Operations

medium

A security engineer is configuring a new SIEM correlation rule to detect lateral movement. Which of the following log sources would provide the most relevant data for detecting pass-the-hash attacks?

0 of 180 answered