フリー問題

Splunk Certified Cybersecurity Defense Analyst のフリー問題 18 / 20 問目

問題文

An analyst is choosing between the stats command and the tstats command for a report. Which considerations correctly guide the choice? (Select two.)

選択肢

  1. The index-time command narrows the search to the summarization range automatically, and so the analyst does not have to think about the time range at all.
  2. The index-time command requires the data model to be accelerated, and so a SOC that has not enabled acceleration has no choice but to use the ordinary aggregation for every report it writes against the common information model.
  3. The ordinary aggregation supports more statistical functions on unnamed inputs, and so it should be used whenever a count without a field argument is needed.
  4. If the aggregation needs a field extracted from the raw text at search time, the index-time command cannot supply it and the ordinary aggregation is required.
  5. If the aggregation needs only fields present at index time or in a data model, the index-time command avoids reading the raw events and runs much faster.

解答・解説を確認するには

正解と解説の確認、回答の記録には無料登録が必要です。登録すると演習モードでフリー問題に回答し、正誤と解説をその場で確認できます。