フリー問題

Splunk Certified Cybersecurity Defense Analyst のフリー問題 15 / 20 問目

問題文

A SOC runs a nightly report that reads 60 days of proxy logs, computes a per-user request count, and then discards all users below a threshold. Only 40 users are above the threshold. Which of these is the false expectation that the team should let go of?

選択肢

  1. That the report will get faster if the time range is reduced to 30 days.
  2. That the report will get faster if the aggregation is rewritten to use indexed fields, a change that lets the nightly run avoid touching the raw events, and the nightly window shrinks, so the report finishes sooner.
  3. That the report will get faster if the source type and index are named explicitly at the start, because naming them lets the platform skip entries that cannot match and therefore reduces the amount of data the search has to read before it aggregates.
  4. That the report will get faster if the final threshold is raised, because that changes only how many rows survive the last step.

解答・解説を確認するには

正解と解説の確認、回答の記録には無料登録が必要です。登録すると演習モードでフリー問題に回答し、正誤と解説をその場で確認できます。