Analysts notice a clerk account querying property-tax records at 2 a.m. from an unusual location. Which monitoring mix best helps confirm anomalous insider-style behavior?
Select an answer to reveal the explanation.
Short Explanation
Weird midnight property-tax clicks deserve more than a poster on the wall. Layer threat intel, hunting, and UEBA so odd hours and odd places light up early. Turning logs off or waiting for ransomware is the expensive way to learn.
Full Explanation
Threat intelligence, hunting, and UEBA complement SIEM monitoring by highlighting anomalous user and entity behavior—such as unusual hours, volume, or locations—against municipal baselines. Combining those techniques improves detection of insider-style misuse before major impact. Awareness alone or disabling telemetry leaves operations blind to behavioral risk.