CertyRush
Đang tải...
C CertyRush
Câu hỏi free preview

Câu 24: SPLK-5002: Splunk Certified Cybersecurity Defense Engineer

When creating a detection, how might an engineer ensure that all possible contextual fields about a given asset and identity are added to a risk event?

Nội dung câu hỏi

When creating a detection, how might an engineer ensure that all possible contextual fields about a given asset and identity are added to a risk event?

Các lựa chọn

Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.

  1. A. Use | lookup identities.csv to call all available identity information in the detection output.
  2. B. Include the standard CIM fields (e.g. user, src, src_user, etc.) in the detection output. — đáp án hiện tại
  3. C. Call an adaptive response action for Active Directory using | ldapsearch for a real-time update.
  4. D. Use | lookup assets.csv to call all available asset information in the detection output.

Cộng đồng

0 bình luận công khai. Tên thành viên được ẩn một phần.

Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.

Câu hỏi liền kề