Which of the following is the first step to take when creating an anomaly detection process?
A.
Selecting events
B.
Building a baseline
C.
Selecting logging options
D.
Creating an event log
The Answer Is:
B
This question includes an explanation.
Explanation:
The first step in creating an anomaly detection process is building a baseline of normal behavior within the system. This baseline serves as a reference point to identify deviations or anomalies that could indicate a security incident. By understanding what normal activity looks like, security teams can more effectively detect and respond to suspicious behavior.