フリー問題

Splunk Certified Cybersecurity Defense Analyst のフリー問題 13 / 20 問目

問題文

An analyst investigates an alert for a large outbound transfer and finds that it was the monthly database export that the finance team runs by design. The activity did happen, it did match what the detection looks for, and it is expected. Which disposition value fits, and why not the others?

選択肢

  1. Benign positive, because the detection correctly identified the activity and the activity was real, but it is expected behavior rather than a threat.
  2. True positive with suspicious activity, because a large outbound transfer is suspicious regardless of who scheduled it, and the size is what the detection flags.
  3. False positive with incorrect analytic logic, because the detection should not have fired on a scheduled export and the fact that it did means the search logic needs to be narrowed before it produces the same alert again next month.
  4. Undetermined, because the analyst cannot prove the export was not misused.

解答・解説を確認するには

正解と解説の確認、回答の記録には無料登録が必要です。登録すると演習モードでフリー問題に回答し、正誤と解説をその場で確認できます。