フリー問題

Splunk Certified Cybersecurity Defense Analyst のフリー問題 2 / 20 問目

問題文

A hospital network runs a SOC with three tiers. Over the past month, one detection has produced 400 alerts and every one of them turned out to be a scheduled backup agent reading many files at once. The team agrees the search logic itself needs a new exclusion for the backup service account. In a SOC organized with separate analyst, engineer, and architect duties, whose work is it to change that search logic, and what does the analyst contribute?

選択肢

  1. The security engineer edits the detection search, and the analyst supplies the evidence from the triaged alerts that shows which account and behavior are producing the noise.
  2. Nobody changes the search logic; the analyst applies a suppression so the alerts stop appearing.
  3. The security architect edits the detection search, since search logic is part of the content design that the architect owns.
  4. The analyst edits the detection search directly, since the analyst is the person who saw the noise and therefore knows which exclusion the queue needs.

解答・解説を確認するには

正解と解説の確認、回答の記録には無料登録が必要です。登録すると演習モードでフリー問題に回答し、正誤と解説をその場で確認できます。