Quiz 7 Question 6 of 20

A SOC receives threat intelligence indicating that an APT group uses a specific user-agent string in HTTP requests. Which SIEM query approach most efficiently detects this across all web proxy logs?

Select an answer to reveal the explanation.

Motivation