問題文
A SOC keeps a lookup table of approved service accounts and wants a search to flag authentication events for accounts that are not in that table. Which arrangement does that, and why is the alternative wrong?
選択肢
- Filter the events with a subsearch that returns the table contents, so the search matches only approved accounts, and that is the set the SOC needs to review.
- Aggregate the events by account and compare the count with the number of rows in the table, since a gap between the two totals shows that an unapproved account signed in.
- Read the table as a set of events and append it to the search results, then keep only the rows that appear once, because an account that exists in both the events and the table will produce two rows while an unapproved account produces only one.
- Enrich the events from the lookup so that a field from the table is added, then keep only the events where that added field is empty.