フリー問題

Splunk Certified Cybersecurity Defense Analyst のフリー問題 19 / 20 問目

問題文

A SOC is deciding which adaptive response actions to attach to a detection for a suspected compromised endpoint. Which choices are appropriate to run automatically on every match? (Select two.)

選択肢

  1. Isolating the host from the network, because that stops the adversary without destroying evidence.
  2. Gathering additional context about the asset and the account involved, because collecting information does not change the environment.
  3. Deleting the file identified by the detection, because removing it prevents reinfection.
  4. Disabling the user account, because acting immediately is what limits the damage and the cost of a wrongly disabled account is lower than the cost of a compromise that spreads while the team is still deciding what to do.
  5. Creating a record in the ticketing system so the work is tracked, because a superfluous ticket can be closed at low cost.

解答・解説を確認するには

正解と解説の確認、回答の記録には無料登録が必要です。登録すると演習モードでフリー問題に回答し、正誤と解説をその場で確認できます。