問題文
A team is asked to report how quickly they detect intrusions. Two candidate definitions are proposed: the interval from the timestamp inside the originating event to the moment the finding was created, and the interval from the moment the finding was created to the moment an analyst claimed it. Which one measures detection speed, and what does the other one measure?
選択肢
- The first measures detection speed, because it spans the gap between the activity happening and the platform noticing it; the second measures how long findings wait in the queue before anyone starts on them in each shift.
- Both measure the same thing with different precision, because the finding creation time and the analyst claim time are always within the detection interval of each other in the report window.
- The second measures detection speed, because detection is not complete until a person has confirmed that the observation is real, while the first measures only the ingestion lag of the data source ahead of it, which is a property of the pipeline itself.
- Neither measures detection speed, because that requires knowing when the intrusion actually started, which is only established during the investigation and cannot be derived from timestamps and the queue times describe only handling.