問題文
A detection engineer wants a rule that fires when a particular administrative API call succeeds outside the approved change window. Which sequence is the sound way to build it?
選択肢
- Find real examples of that call among the ingested cloud events, read the attributes they actually carry, write the conditions against those attributes, and check the result against historical activity before relying on it.
- Ask the cloud platform team to add a tag to every approved change so that the rule can match on the tag alone, which removes the need to express any condition about the time of the operation or about which identity carried it out.
- Write the conditions from the provider documentation without looking at the ingested records, because the documented field names are authoritative.
- Enable the rule immediately with broad conditions and narrow it later based on the volume of matches it produces during the first week of operation, treating that week as the tuning period and accepting whatever reaches the queue while the conditions settle.