フリー問題

Splunk Certified Cybersecurity Defense Analyst のフリー問題 1 / 20 問目

問題文

A financial services SOC wants its correlation searches to carry mappings to more than one industry framework so that different audiences can read the same alert. Which statements correctly describe what the Annotations section of a correlation search in Splunk Enterprise Security supports? (Select two.)

選択肢

  1. Several named frameworks can be annotated on the same correlation search, including CIS 20, the Lockheed Martin Cyber Kill Chain, MITRE ATT&CK, and NIST.
  2. The annotated values appear as field labels when an analyst looks at the resulting alert, so the framework context travels with the alert into triage.
  3. Annotating a correlation search automatically adds it to the use case library so that the framework filter can find it without any further work from the engineer.
  4. The annotation replaces the severity value that the correlation search assigns, so the framework mapping is what drives the urgency of the resulting alert.
  5. Only the frameworks that ship with predefined values can be annotated; a SOC that uses an internal control catalog has to keep that mapping outside Splunk in a separate document.

解答・解説を確認するには

正解と解説の確認、回答の記録には無料登録が必要です。登録すると演習モードでフリー問題に回答し、正誤と解説をその場で確認できます。