C_SEC_2405 · Question #47
What happens to data within SAP Enterprise Threat Detection during the aggregation process? Note: There are 3 correct answers to this question.
The correct answer is C. It is pseudonymized. D. It is normalized. E. It is enriched. During SAP Enterprise Threat Detection's aggregation process, incoming security log data from various SAP systems is normalized (D) - converted into a unified format regardless of source - pseudonymized (C) - replacing personally identifiable information like usernames with…
Question
What happens to data within SAP Enterprise Threat Detection during the aggregation process? Note: There are 3 correct answers to this question.
Options
- AIt is prioritized.
- BIt is categorized.
- CIt is pseudonymized.
- DIt is normalized.
- EIt is enriched.
How the community answered
(27 responses)- A7% (2)
- B15% (4)
- C78% (21)
Explanation
During SAP Enterprise Threat Detection's aggregation process, incoming security log data from various SAP systems is normalized (D) - converted into a unified format regardless of source - pseudonymized (C) - replacing personally identifiable information like usernames with tokens to comply with privacy regulations such as GDPR - and enriched (E) - supplemented with additional context (e.g., user roles, system metadata, threat intelligence) to make raw events actionable for analysts.
Prioritization (A) occurs later during alert triage or investigation workflows, not during aggregation. Categorization (B) is not a defined step in SAP ETD's aggregation pipeline; while events are processed, formal categorization is distinct from the normalization/enrichment pipeline.
Memory tip: Use the acronym NPE - Normalize, Pseudonymize, Enrich - the three things aggregation does to raw data before it can be analyzed. Think of it as "prepping" the data: same shape (normalized), privacy-safe (pseudonymized), and context-rich (enriched).
Topics
Community Discussion
No community discussion yet for this question.