nerdexam
Splunk

SPLK-5002 · Question #30

When creating a detection that searches user activity across CIM-compliant data, which CIM field should be reviewed to ensure that data is aggregated appropriately?

The correct answer is D. user. The user field is the normalized CIM field for user activity across data sources. Reviewing and using this field ensures that data from different sources is properly aggregated, enabling consistent detection logic across CIM-compliant datasets.

Advanced Security Data Onboarding

Question

When creating a detection that searches user activity across CIM-compliant data, which CIM field should be reviewed to ensure that data is aggregated appropriately?

Options

  • Auserid
  • Bidentity
  • CsrcUser
  • Duser

How the community answered

(35 responses)
  • A
    3% (1)
  • B
    11% (4)
  • C
    9% (3)
  • D
    77% (27)

Explanation

The user field is the normalized CIM field for user activity across data sources. Reviewing and using this field ensures that data from different sources is properly aggregated, enabling consistent detection logic across CIM-compliant datasets.

Topics

#CIM field normalization#user field#data aggregation#detection engineering

Community Discussion

No community discussion yet for this question.

Full SPLK-5002 Practice