問題文
The team wants an entity to reach the analyst queue once its accumulated risk crosses a defined level within a rolling period. In Splunk Enterprise Security 8.x, which construct produces that behavior?
選択肢
- A risk factor whose condition tests the accumulated total, so the framework raises a finding the moment the multiplication pushes the entity over the level, which the risk factor evaluates.
- An adaptive response action attached to each contributing detection, which checks the entity's total after every contribution and creates a finding when the level is reached at that moment in the run.
- A finding-based detection that aggregates the intermediate findings for an entity and raises a finding when the total passes the level the engineer defines in advance.
- An event-based detection with its output set to create findings and its search filtered on the risk index, which is equivalent because the risk index holds the accumulated scores and the filter on that index is what makes it work.