Splunk
SPLK-3001 · Question #32
SPLK-3001 Question #32: Real Exam Question with Answer & Explanation
Sign in or unlock SPLK-3001 to reveal the answer and full explanation for question #32. The question stem and answer options stay visible for context.
Question
The Brute Force Access Behavior Detected correlation search is enabled, and is generating many false positives. Assuming the input data has already been validated. How can the correlation search be made less sensitive?
Options
- AEdit the search and modify the notable event status field to make the notable events less urgent.
- BEdit the search, look for where or xswhere statements, and after the threshold value being
- CEdit the search, look for where or xswhere statements, and alter the threshold value being
- DModify the urgency table for this correlation search and add a new severity level to make notable
Unlock SPLK-3001 to see the answer
You've previewed enough free SPLK-3001 questions. Unlock SPLK-3001 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.