CertyRush
Đang tải...
C CertyRush
Câu hỏi free preview

Câu 28: SPLK-5002: Splunk Certified Cybersecurity Defense Engineer

Consider the following series of events:4:00 GMT Detection runs for interval 3:30-4:004:30 GMT Detection runs for interval 4:00-4:304:35 GMT Event 1 occurs on an endpoint4:45 GMT Event 1 is indexed5:00 GMT Detection runs for interval 4:30-5:005:05 GMT Event 1 finding is added to ES with timestamp 4:355:24 GMT Event 2…

Nội dung câu hỏi

Consider the following series of events:4:00 GMT Detection runs for interval 3:30-4:004:30 GMT Detection runs for interval 4:00-4:304:35 GMT Event 1 occurs on an endpoint4:45 GMT Event 1 is indexed5:00 GMT Detection runs for interval 4:30-5:005:05 GMT Event 1 finding is added to ES with timestamp 4:355:24 GMT Event 2 occurs on an endpoint5:30 GMT Detection runs for interval 5:00-5:305:35 GMT Event 2 is indexed6:00 GMT Detection runs for interval 5:30-6:00What is the problem with the detection schedule chosen and how can it be solved?

Các lựa chọn

Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.

  1. A. The time window for the detection is too large, causing duplicate alerts.
  2. B. The logs are delayed so the detection time window needs to be increased. — đáp án hiện tại
  3. C. The time window for the detection is too small, causing duplicate alerts.
  4. D. The logs are delayed so the detection time window needs to be decreased.

Cộng đồng

0 bình luận công khai. Tên thành viên được ẩn một phần.

Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.

Câu hỏi liền kề