フリー問題

Splunk Certified Cybersecurity Defense Engineer のフリー問題 11 / 20 問目

問題文

An organization's own vulnerability scanners appear in threat matches every day because their addresses were once published in an open feed. The team wants to stop these matches without editing the feed. What should they do, and what should they be careful about?

選択肢

  1. Move the scanners to a dedicated index that the threat matching searches do not read, which removes them from the comparison entirely at index time.
  2. Add the scanners' addresses to a safelist so the matching searches skip them, and record why each entry exists so a future engineer does not silently keep a genuinely malicious address excluded.
  3. Remove the open feed and rely only on the commercial sources, because a feed that lists internal addresses is not trustworthy enough to keep, which settles the question.
  4. Lower the severity of the threat matching detections so the daily matches no longer reach the analyst queue, which keeps the coverage intact without maintaining an exclusion list for the scanner ranges each week.

解答・解説を確認するには

正解と解説の確認、回答の記録には無料登録が必要です。登録すると演習モードでフリー問題に回答し、正誤と解説をその場で確認できます。