Splunk
SPLK-5001 · Question #98
Enterprise Security has been configured to generate a Notable Event when a user has quickly authenticated from multiple locations between which travel would be impossible. This would be considered…
The correct answer is C. Identity Anomaly. “Impossible travel” detections fall under Identity Anomalies in Splunk ES, as they flag unusual or impossible user authentication behavior tied to a specific identity.
Threat Detection and Alerting
Question
Enterprise Security has been configured to generate a Notable Event when a user has quickly authenticated from multiple locations between which travel would be impossible. This would be considered what kind of an anomaly?
Options
- AAccess Anomaly
- BEndpoint Anomaly
- CIdentity Anomaly
- DThreat Anomaly
How the community answered
(35 responses)- A14% (5)
- B6% (2)
- C71% (25)
- D9% (3)
Explanation
“Impossible travel” detections fall under Identity Anomalies in Splunk ES, as they flag unusual or impossible user authentication behavior tied to a specific identity.
Topics
#impossible travel#identity anomaly#Splunk ES#authentication
Community Discussion
No community discussion yet for this question.