nerdexam
Splunk

SPLK-5002 · Question #114

A company wants to implement risk-based detection for privileged account activities. What should they configure first?

The correct answer is A. Asset and identity information for privileged accounts. Why Configure Asset & Identity Information for Privileged Accounts First? Risk-based detection focuses on identifying and prioritizing threats based on the severity of their impact. For privileged accounts (admins, domain controllers, finance users), understanding who they are…

Advanced Threat Hunting and Analytics

Question

A company wants to implement risk-based detection for privileged account activities. What should they configure first?

Options

  • AAsset and identity information for privileged accounts
  • BCorrelation searches with low thresholds
  • CEvent sampling for raw data
  • DAutomated dashboards for all accounts

How the community answered

(49 responses)
  • A
    80% (39)
  • B
    4% (2)
  • C
    10% (5)
  • D
    6% (3)

Explanation

Why Configure Asset & Identity Information for Privileged Accounts First? Risk-based detection focuses on identifying and prioritizing threats based on the severity of their impact. For privileged accounts (admins, domain controllers, finance users), understanding who they are, what they access, and how they behave is critical. Key Steps for Risk-Based Detection in Splunk ES: 1. Define Privileged Accounts & Groups - Identify high-risk users (Admin, HR, Finance, CISO). 2. Assign Risk Scores - Apply higher scores to actions involving privileged users. 3. Enable Identity & Asset Correlation - Link users to assets for better detection. 4. Monitor for Anomalies - Detect abnormal login patterns, excessive file access, or unusual privilege escalation.

Topics

#risk-based detection#privileged accounts#asset identity#threat detection

Community Discussion

No community discussion yet for this question.

Full SPLK-5002 Practice