フリー問題

Splunk Certified Cybersecurity Defense Analyst のフリー問題 5 / 20 問目

問題文

A detection engineer at a utility company adds MITRE ATT&CK technique identifiers to the Annotations section of 40 correlation searches. What does the engineer gain from this work, stated in terms of what an analyst or a manager can now do?

選択肢

  1. The correlation searches appear in the use case library under the framework filter without further work, and the analysts can then browse the SOC's own detections beside the shipped content.
  2. The alerts are automatically assigned a higher urgency when the annotated technique is one that the framework marks as high impact, so the queue reorders itself once the mapping is saved.
  3. The correlation searches begin to run against the accelerated data models associated with each technique, and that reduces the time each search takes and therefore lets the engineer schedule all 40 of them in the same window.
  4. Alerts arrive carrying the framework mapping as labeled fields, and the coverage across the framework can be summarized to show which parts of it no detection touches.

解答・解説を確認するには

正解と解説の確認、回答の記録には無料登録が必要です。登録すると演習モードでフリー問題に回答し、正誤と解説をその場で確認できます。