フリー問題

Splunk Certified Cybersecurity Defense Analyst のフリー問題 11 / 20 問目

問題文

A SOC configures throttling on a detection with a window and a set of grouping fields. Which statements about how that behaves are correct? (Select two.)

選択肢

  1. Throttling reduces the number of results the search returns, and so the search itself runs faster.
  2. Editing the throttle configuration extends the current window, and so the change takes effect only after the window that was already running has expired.
  3. Throttling is evaluated before the trigger conditions, so a result that would be throttled never reaches the trigger condition evaluation and the two settings therefore cannot interact in a way that produces unexpected numbers of actions.
  4. If a grouping field named in the configuration is absent from the search results, all results are treated as matching each other and therefore all are throttled.
  5. During the window, a result whose grouping field values match a previous result produces no new action, and after the window ends the next matching result starts a new window.

解答・解説を確認するには

正解と解説の確認、回答の記録には無料登録が必要です。登録すると演習モードでフリー問題に回答し、正誤と解説をその場で確認できます。