フリー問題

Splunk Certified Cybersecurity Defense Engineer のフリー問題 14 / 20 問目

問題文

A team writes a standard operating procedure for handling findings from a phishing detection. At what level of detail should it be written to remain useful?

選択肢

  1. Detailed enough to be executable by an automation platform without human interpretation, because a procedure that cannot be automated is a procedure that has not been thought through in the first place.
  2. As briefly as possible, listing only the decision points, because analysts are trained professionals and a longer document will not be read under time pressure in the queue.
  3. Detailed enough to include the full search strings the analyst should run, because reproducing the engineer's queries is the fastest path to the same conclusion for the analyst on the night shift.
  4. Detailed enough that it names which fields on the finding to read and what decision each observation supports, but not so detailed that it hard-codes screen positions or exact click paths that change with each release of the product console.

解答・解説を確認するには

正解と解説の確認、回答の記録には無料登録が必要です。登録すると演習モードでフリー問題に回答し、正誤と解説をその場で確認できます。