nerdexam
Splunk

SPLK-5002 · Question #107

Which action improves the effectiveness of notable events in Enterprise Security?

The correct answer is A. Applying suppression rules for false positives. Notable events in Splunk Enterprise Security (ES) are triggered by correlation searches, which generate alerts when suspicious activity is detected. However, if too many false positives occur, analysts waste time investigating non-issues, reducing SOC efficiency. How to Improve…

Custom Content Development

Question

Which action improves the effectiveness of notable events in Enterprise Security?

Options

  • AApplying suppression rules for false positives
  • BDisabling scheduled searches
  • CUsing only raw log data in searches
  • DLimiting the search scope to one index

How the community answered

(54 responses)
  • A
    81% (44)
  • B
    4% (2)
  • C
    9% (5)
  • D
    6% (3)

Explanation

Notable events in Splunk Enterprise Security (ES) are triggered by correlation searches, which generate alerts when suspicious activity is detected. However, if too many false positives occur, analysts waste time investigating non-issues, reducing SOC efficiency. How to Improve Notable Events Effectiveness: Apply suppression rules to filter out known false positives and reduce alert fatigue. Refine correlation searches by adjusting thresholds and tuning event detection logic. Leverage risk-based alerting (RBA) to prioritize high-risk events. Use adaptive response actions to enrich events dynamically. By suppressing false positives, SOC analysts focus on real threats, making notable events more actionable. Thus, the correct answer is A. Applying suppression rules for false positives.

Topics

#notable events#suppression rules#false positives#Enterprise Security

Community Discussion

No community discussion yet for this question.

Full SPLK-5002 Practice