Quiz 5 Question 10 of 20

A SOAR playbook uses an AI assistant to summarize a suspicious authentication alert. The summary states the user downloaded malware from a phishing site, but the SIEM only shows a failed login and no file transfer. What should the analyst do first?

Select an answer to reveal the explanation.

Motivation