CertyRush
Đang tải...
C CertyRush
Câu hỏi free preview

Câu 27: SPLK-5003: Splunk Certified Cybersecurity Defense Architect

Kevin is a SOC analyst working with the SRE team to investigate a report of slow responses from a customer-facing web application. While looking at load balancer and WAF logs, Kevin has discovered that one of the web servers hosting the application has gone offline. He does not see any alerts in the WAF or from the en…

Nội dung câu hỏi

Kevin is a SOC analyst working with the SRE team to investigate a report of slow responses from a customer-facing web application. While looking at load balancer and WAF logs, Kevin has discovered that one of the web servers hosting the application has gone offline. He does not see any alerts in the WAF or from the endpoint detection and response agent running on the web server. As part of triaging this incident, what should they do next? (Choose all that apply.)

Các lựa chọn

Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.

  1. A. Change the WAF from blocking mode to alert-only mode.
  2. B. Review recently scheduled requests in the company’s change management system that may affect the same server. — đáp án hiện tại
  3. C. Provision a new server behind the load balancer to return the application to full service.
  4. D. Review system logs collected from the server to identify who last logged into it. — đáp án hiện tại

Cộng đồng

0 bình luận công khai. Tên thành viên được ẩn một phần.

Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.

Câu hỏi liền kề