フリー問題

Splunk Certified Cybersecurity Defense Engineer のフリー問題 4 / 20 問目

問題文

A detection that reports credential stuffing against a login portal creates one alert per matching event, so a single burst produces dozens of entries. The engineer opens the throttling section of the detection editor. What should be entered in the fields to group by, and what does that setting do?

選択肢

  1. The name of the field that holds the severity, so that alerts of the same severity are collapsed and the analyst sees one entry per severity level per window in the analyst queue.
  2. The values that should be ignored, such as the addresses of the known load balancers, so that results carrying those values are dropped for the duration of the window, which the window enforces on each run.
  3. The names of the fields that identify one occurrence, such as the target account and the source address; while the window lasts, a result matching all of those field values does not create another alert until the window ends.
  4. The name of a single field with the highest cardinality, because grouping by more than one field disables the window and every result is reported again on each run.

解答・解説を確認するには

正解と解説の確認、回答の記録には無料登録が必要です。登録すると演習モードでフリー問題に回答し、正誤と解説をその場で確認できます。