nerdexam
Splunk

SPLK-5002 · Question #32

Which type of correlation search reviews the events in the risk index and uses an aggregation of events impacting a single risk object to generate risk notables?

The correct answer is A. Risk Incident Rule. A Risk Incident Rule correlation search reviews the events stored in the risk index and aggregates them by risk object (such as a user or asset). When the combined risk score crosses a defined threshold, it generates a risk notable in Enterprise Security.

Advanced Threat Hunting and Analytics

Question

Which type of correlation search reviews the events in the risk index and uses an aggregation of events impacting a single risk object to generate risk notables?

Options

  • ARisk Incident Rule
  • BRisk Category
  • CRisk Incident Notable
  • DRisk Rule

How the community answered

(45 responses)
  • A
    78% (35)
  • B
    4% (2)
  • C
    4% (2)
  • D
    13% (6)

Explanation

A Risk Incident Rule correlation search reviews the events stored in the risk index and aggregates them by risk object (such as a user or asset). When the combined risk score crosses a defined threshold, it generates a risk notable in Enterprise Security.

Topics

#Risk Incident Rule#risk index#risk notables#correlation search

Community Discussion

No community discussion yet for this question.

Full SPLK-5002 Practice