フリー問題

Splunk Certified Cybersecurity Defense Analyst のフリー問題 10 / 20 問目

問題文

A hospital SOC gets an alert that a nurse's account read 4,000 patient records in one hour. The SOC needs to decide whether this is unusual for that role before escalating. Which data source answers that question, and why do the others fall short?

選択肢

  1. The Authentication data model, because a successful login is the precondition for the reads and a login from an unexpected location would explain the volume without requiring the SOC to build any baseline of normal behavior at all.
  2. The application's own access records over the previous weeks, because the comparison the SOC needs is against how much this role normally reads.
  3. The Endpoint data model, because the process that made the reads can be identified there together with the count of records that process touched.
  4. The Network Traffic data model, because 4,000 record reads produce measurable traffic, and an hour of reads on that scale stands out against the ward's usual volume.

解答・解説を確認するには

正解と解説の確認、回答の記録には無料登録が必要です。登録すると演習モードでフリー問題に回答し、正誤と解説をその場で確認できます。