Question 6 of 60

After working with an Offense, an analyst set the Offense as hidden. What does the analyst need to do to view the Offense at a later time?
Answer

Suggested Answer

The suggested answer is C.

Community Votes

No votes yet

Join the discussion to cast yours

Question 7 of 60

What is the reason for this system notification?
Exam C1000-018: Question 7 - Image 1
Answer

Suggested Answer

The suggested answer is D.

Community Votes

No votes yet

Join the discussion to cast yours

Question 8 of 60

When an analyst sees the system notification “The appliance exceeded the EPS or FPM allocation within the last hour”, how does the analyst resolve this issue? (Choose two.)
Answer

Suggested Answer

The suggested answer is B, C.

Community Votes

No votes yet

Join the discussion to cast yours

Question 9 of 60

An analyst is encountering a large number of false positive results. Legitimate internal network traffic contains valid flows and events which are making it difficult to identify true security incidents.
What can the analyst do to reduce these false positive indicators?
Answer

Suggested Answer

The suggested answer is C.

Community Votes

No votes yet

Join the discussion to cast yours

Question 10 of 60

What is the maximum time period for 3 subsequent events to be coalesced?
Answer

Suggested Answer

The suggested answer is B.

Community Votes

No votes yet

Join the discussion to cast yours