Câu 11: SPLK-5003: Splunk Certified Cybersecurity Defense Architect
Emma is a security architect helping migrate her organization’s on-premises SIEM to a newer version of the same SIEM running in a cloud provider. The newer version includes enhanced capabilities for writing detection content. The detection engineering team has built hundreds of rules in the on-premises SIEM over the y…
Nội dung câu hỏi
Emma is a security architect helping migrate her organization’s on-premises SIEM to a newer version of the same SIEM running in a cloud provider. The newer version includes enhanced capabilities for writing detection content. The detection engineering team has built hundreds of rules in the on-premises SIEM over the years. As Emma starts planning for the migration, what should she do about moving the detection rules to the new platform?
Các lựa chọn
Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.
- A. Export half of the rules from the SIEM and manually convert them.
- B. Nothing, the newer version’s default detection content will cover the organization’s needs.
- C. Export all of the rules from the SIEM in Sigma format and import them into the new platform.
- D. Review which rules are still relevant to the organization’s threat models to prioritize for migration. — đáp án hiện tại
Cộng đồng
0 bình luận công khai. Tên thành viên được ẩn một phần.