Splunk
SPLK-5001 · Question #49
An analyst is attempting to investigate a Notable Event within Enterprise Security. Through the course of their investigation they determined that the logs and artifacts needed to investigate the aler
Sign in or unlock SPLK-5001 to reveal the answer and full explanation for question #49. The question stem and answer options stay visible for context.
Incident Investigation and Response
Question
An analyst is attempting to investigate a Notable Event within Enterprise Security. Through the course of their investigation they determined that the logs and artifacts needed to investigate the alert are not available. What event disposition should the analyst assign to the Notable Event?
Options
- ABenign Positive, since there was no evidence that the event actually occurred.
- BFalse Negative, since there are no logs to prove the activity actually occurred.
- CTrue Positive, since there are no logs to prove that the event did not occur.
- DOther, since a security engineer needs to ingest the required logs.
Unlock SPLK-5001 to see the answer
You've previewed enough free SPLK-5001 questions. Unlock SPLK-5001 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.
Topics
#notable events#event disposition#incident investigation#Enterprise Security