SPLK-5002 · Question #114
A company wants to implement risk-based detection for privileged account activities. What should they configure first?
The correct answer is A. Asset and identity information for privileged accounts. Why Configure Asset & Identity Information for Privileged Accounts First? Risk-based detection focuses on identifying and prioritizing threats based on the severity of their impact. For privileged accounts (admins, domain controllers, finance users), understanding who they are…
Question
A company wants to implement risk-based detection for privileged account activities. What should they configure first?
Options
- AAsset and identity information for privileged accounts
- BCorrelation searches with low thresholds
- CEvent sampling for raw data
- DAutomated dashboards for all accounts
How the community answered
(49 responses)- A80% (39)
- B4% (2)
- C10% (5)
- D6% (3)
Explanation
Why Configure Asset & Identity Information for Privileged Accounts First? Risk-based detection focuses on identifying and prioritizing threats based on the severity of their impact. For privileged accounts (admins, domain controllers, finance users), understanding who they are, what they access, and how they behave is critical. Key Steps for Risk-Based Detection in Splunk ES: 1. Define Privileged Accounts & Groups - Identify high-risk users (Admin, HR, Finance, CISO). 2. Assign Risk Scores - Apply higher scores to actions involving privileged users. 3. Enable Identity & Asset Correlation - Link users to assets for better detection. 4. Monitor for Anomalies - Detect abnormal login patterns, excessive file access, or unusual privilege escalation.
Topics
Community Discussion
No community discussion yet for this question.