nerdexam
Splunk

SPLK-5001 · Question #98

Enterprise Security has been configured to generate a Notable Event when a user has quickly authenticated from multiple locations between which travel would be impossible. This would be considered…

The correct answer is C. Identity Anomaly. “Impossible travel” detections fall under Identity Anomalies in Splunk ES, as they flag unusual or impossible user authentication behavior tied to a specific identity.

Threat Detection and Alerting

Question

Enterprise Security has been configured to generate a Notable Event when a user has quickly authenticated from multiple locations between which travel would be impossible. This would be considered what kind of an anomaly?

Options

  • AAccess Anomaly
  • BEndpoint Anomaly
  • CIdentity Anomaly
  • DThreat Anomaly

How the community answered

(35 responses)
  • A
    14% (5)
  • B
    6% (2)
  • C
    71% (25)
  • D
    9% (3)

Explanation

“Impossible travel” detections fall under Identity Anomalies in Splunk ES, as they flag unusual or impossible user authentication behavior tied to a specific identity.

Topics

#impossible travel#identity anomaly#Splunk ES#authentication

Community Discussion

No community discussion yet for this question.

Full SPLK-5001 Practice