問題文
An analyst who is new to Wiz Defend asks how a single record written by a cloud provider ends up as work on an analyst queue. Which sequence describes the platform correctly?
選択肢
- Cloud events are held unprocessed until an analyst opens the detections area, at which point the rules are evaluated against everything that has accumulated in the meantime.
- A threat is raised first from the provider record, and detections are then generated underneath it so that the analyst can see which rules would have matched.
- A cloud event is ingested, a Threat Detection Rule that matches it produces a detection, related detections are correlated into a threat, and the threat is where response actions are chosen.
- Every ingested cloud event becomes a threat, and the rules decide only how urgent each threat is.