問題文
A threat has been investigated, the compromised credential has been revoked, and the analyst is ready to close it. Which understanding of the state of a threat is correct?
選択肢
- The state records what the team has decided and done about the situation, so closing it is a statement by the analyst rather than something the platform infers on its own.
- The state changes on its own once no further detections arrive for a period, because silence indicates the situation has ended.
- The state is synchronized from the downstream ticketing system, so the correct way to close a threat is to close the corresponding ticket and wait for the change to propagate back, which keeps the two systems from disagreeing about what has been handled.
- The state cannot be changed by an analyst, because the platform owns the lifecycle of a threat and closing it by hand would break the correlation that assembled it in the first place.