フリー問題

Splunk Certified Cybersecurity Defense Analyst のフリー問題 16 / 20 問目

問題文

A SOC keeps a lookup table of approved service accounts and wants a search to flag authentication events for accounts that are not in that table. Which arrangement does that, and why is the alternative wrong?

選択肢

  1. Filter the events with a subsearch that returns the table contents, so the search matches only approved accounts, and that is the set the SOC needs to review.
  2. Aggregate the events by account and compare the count with the number of rows in the table, since a gap between the two totals shows that an unapproved account signed in.
  3. Read the table as a set of events and append it to the search results, then keep only the rows that appear once, because an account that exists in both the events and the table will produce two rows while an unapproved account produces only one.
  4. Enrich the events from the lookup so that a field from the table is added, then keep only the events where that added field is empty.

解答・解説を確認するには

正解と解説の確認、回答の記録には無料登録が必要です。登録すると演習モードでフリー問題に回答し、正誤と解説をその場で確認できます。