Question 1 of 30
In a security operations center (SOC), a security analyst is tasked with identifying anomalous user behavior that could indicate a potential insider threat. The analyst utilizes a behavioral analytics tool that monitors user activities and generates a baseline of normal behavior. After a week of monitoring, the tool flags a user who has accessed sensitive files outside of their usual working hours and from an unusual location. Given this scenario, which approach should the analyst take to further investigate the flagged behavior effectively?
Correlate the flagged activity with the user's historical access patterns and contextual factors such as recent changes in job responsibilities or personal circumstances.
Immediately escalate the incident to the incident response team without further investigation.
Dismiss the alert as a false positive since the user has accessed sensitive files before.
Block the user's access to sensitive files until the investigation is complete.

Preparing for Microsoft SC-200 Microsoft Security Operations Analyst? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free