フリー問題

Splunk Certified Cybersecurity Defense Analyst のフリー問題 17 / 20 問目

問題文

A SOC wants, per account, the count of distinct destination hosts contacted and the first and last times each account was seen, over 30 days, using only fields present at index time. Which combination achieves that most efficiently?

選択肢

  1. Aggregate with the ordinary command and accept the slower run, because the boundary timestamps are only available to that command.
  2. Group the events into transactions by the account and read the duration, since the transaction command reports the boundary times and the group size for free.
  3. One index-time aggregation grouped by the account, computing the distinct count and the boundary timestamps in the same step.
  4. An index-time aggregation for the distinct count followed by a separate ordinary aggregation for the timestamps, joined on the account, because the boundary timestamps require reading the raw events in order to establish the exact time each account was first and last observed in the data.

解答・解説を確認するには

正解と解説の確認、回答の記録には無料登録が必要です。登録すると演習モードでフリー問題に回答し、正誤と解説をその場で確認できます。