16
How would you detect suspicious attacker behavior in logs or telemetry?
Tap to write answer
0 words | 0 charsPress Enter ↵ to reveal
Your Attempt
0 wordsRefined Model Answer
ReferenceI would define the normal baseline first, then look for anomalies such as repeated failures, unusual access patterns, privilege escalation attempts, and unexpected data transfers. Detection works best when it is tied to concrete attacker techniques, not just generic noise. A strong answer includes both signal quality and response readiness.