Question 1 of 28
In a hybrid cloud environment, a company is implementing a threat protection strategy to safeguard its sensitive data stored both on-premises and in the cloud. The security team is considering various methods to enhance their threat detection capabilities. They are particularly interested in a solution that integrates machine learning to analyze user behavior and identify anomalies that could indicate potential security threats. Which approach should the team prioritize to effectively utilize machine learning for threat detection?
Implementing a User and Entity Behavior Analytics (UEBA) solution that leverages machine learning algorithms to establish baselines of normal user behavior and detect deviations from these patterns.
Deploying a traditional signature-based antivirus solution that relies on known malware signatures to detect threats.
Utilizing a firewall with predefined rules that block known malicious IP addresses without any adaptive learning capabilities.
Setting up a manual log analysis process where security analysts review logs daily to identify potential threats.