A SOAR playbook for insider threat detection needs to correlate data from multiple sources. Which combination best supports this use case?
-
A
Firewall logs and antivirus alerts only
-
B
DLP alerts, user behavior analytics (UBA), HR termination feeds, and access logs
-
C
Patch management reports and vulnerability scanner output
-
D
Email gateway spam filters and DNS query logs