問題文
A security team wants the discovery events of an onboarded cloud account to reach the collector that the rest of the estate already reports to. Which description of those events matches the documentation?
選択肢
- They carry the verdict of the inspection engine instead of anything the provider wrote down, which means one appears for an asset only once that asset starts sending traffic through a checking point.
- They stay inside the product alone and have to be pulled through the reporting interface on a schedule, because the investigate section is where such events can be read.
- They arrive in two categories, one for name resolution and one for flow records, each pairing threat intelligence with what the provider had gathered for the account in question.
- They arrive as a single stream and are divided at the far end by the tag naming the provider, so one profile serves every account and the estate configures just one destination.