フリー問題

Splunk Certified Cybersecurity Defense Analyst のフリー問題 12 / 20 問目

問題文

A detection engineer is configuring a risk analysis response action. Which statements about what gets recorded and what it is used for are correct? (Select two.)

選択肢

  1. The recorded entries replace the raw events, so the original events can be aged out of the index sooner and the SOC can reduce its retention costs without losing the ability to investigate the behaviors that produced each score.
  2. Each recorded entry names the object the risk is attributed to, so scores accumulate per asset or per identity rather than globally.
  3. Each recorded entry immediately appears in the analyst queue with an urgency derived from its score.
  4. Entries can be annotated with framework mappings, so the accumulation can be evaluated not only by total score but also by how many distinct tactics were observed.
  5. A risk factor that multiplies the score for privileged accounts creates its own entry in the analyst queue so that the analyst knows the multiplier was applied.

解答・解説を確認するには

正解と解説の確認、回答の記録には無料登録が必要です。登録すると演習モードでフリー問題に回答し、正誤と解説をその場で確認できます。