問題文
A detection that reports credential stuffing against a login portal creates one alert per matching event, so a single burst produces dozens of entries. The engineer opens the throttling section of the detection editor. What should be entered in the fields to group by, and what does that setting do?
選択肢
- The name of the field that holds the severity, so that alerts of the same severity are collapsed and the analyst sees one entry per severity level per window in the analyst queue.
- The values that should be ignored, such as the addresses of the known load balancers, so that results carrying those values are dropped for the duration of the window, which the window enforces on each run.
- The names of the fields that identify one occurrence, such as the target account and the source address; while the window lasts, a result matching all of those field values does not create another alert until the window ends.
- The name of a single field with the highest cardinality, because grouping by more than one field disables the window and every result is reported again on each run.