CompTIA Security+ SY0-601 – Question562

During an incident, an EDR system detects an increase in the number of encrypted outbound connections from multiple hosts. A firewall is also reporting an increase in outbound connections that use random high ports. An analyst plans to review the correlated logs to find the source of the incident. Which of the following tools will best assist the analyst?


A.
A vulnerability scanner
B. A NGFW
C. The Windows Event Viewer
D. A SIEM

Correct Answer: D