Câu 28: SPLK-5002: Splunk Certified Cybersecurity Defense Engineer
Consider the following series of events:4:00 GMT Detection runs for interval 3:30-4:004:30 GMT Detection runs for interval 4:00-4:304:35 GMT Event 1 occurs on an endpoint4:45 GMT Event 1 is indexed5:00 GMT Detection runs for interval 4:30-5:005:05 GMT Event 1 finding is added to ES with timestamp 4:355:24 GMT Event 2…
Nội dung câu hỏi
Consider the following series of events:4:00 GMT Detection runs for interval 3:30-4:004:30 GMT Detection runs for interval 4:00-4:304:35 GMT Event 1 occurs on an endpoint4:45 GMT Event 1 is indexed5:00 GMT Detection runs for interval 4:30-5:005:05 GMT Event 1 finding is added to ES with timestamp 4:355:24 GMT Event 2 occurs on an endpoint5:30 GMT Detection runs for interval 5:00-5:305:35 GMT Event 2 is indexed6:00 GMT Detection runs for interval 5:30-6:00What is the problem with the detection schedule chosen and how can it be solved?
Các lựa chọn
Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.
- A. The time window for the detection is too large, causing duplicate alerts.
- B. The logs are delayed so the detection time window needs to be increased. — đáp án hiện tại
- C. The time window for the detection is too small, causing duplicate alerts.
- D. The logs are delayed so the detection time window needs to be decreased.
Cộng đồng
0 bình luận công khai. Tên thành viên được ẩn một phần.