ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 30 - SPLK-5001 discussion

Report
Export

A Risk Rule generates events on Suspicious Cloud Share Activity and regularly contributes to confirmed incidents from Risk Notables. An analyst realizes the raw logs these events are generated from contain information which helps them determine what might be malicious.

What should they ask their engineer for to make their analysis easier?

A.
Create a field extraction for this information.
Answers
A.
Create a field extraction for this information.
B.
Add this information to the risk message.
Answers
B.
Add this information to the risk message.
C.
Create another detection for this information.
Answers
C.
Create another detection for this information.
D.
Allowlist more events based on this information.
Answers
D.
Allowlist more events based on this information.
Suggested answer: A
asked 23/09/2024
Nisanka Mandara
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first