フリー問題

Splunk Certified Cybersecurity Defense Analyst のフリー問題 9 / 20 問目

問題文

A correlation search generates an alert with a severity of high. The asset involved has a priority of critical in the asset lookup. In Splunk Enterprise Security's default arrangement, what urgency does the resulting alert carry, and what produced it?

選択肢

  1. Critical, because the urgency always takes the higher of the two values.
  2. Unknown, because the asset priority is not part of the urgency calculation until asset and identity correlation is enabled, and nothing can be scored before that runs once.
  3. Critical, produced by looking up the combination of the severity from the search and the priority from the asset in a lookup that maps the two onto an urgency value.
  4. High, because the urgency always takes the severity value that the correlation search assigned and the asset priority is used only for sorting the queue, and that means changing the priority in the lookup would not affect the urgency shown on the alert.

解答・解説を確認するには

正解と解説の確認、回答の記録には無料登録が必要です。登録すると演習モードでフリー問題に回答し、正誤と解説をその場で確認できます。