nerdexam
Splunk

SPLK-5002 · Question #51

What is Enterprise Security's default way of determining the urgency of a finding (notable event)?

The correct answer is D. Take into account the priority assigned to the asset/identity as well as the severity value assigned. In Splunk Enterprise Security, the default method for determining the urgency of a notable event considers both the priority of the asset or identity involved and the severity value assigned to the finding. This ensures that critical assets with high-severity events are…

Advanced Threat Hunting and Analytics

Question

What is Enterprise Security's default way of determining the urgency of a finding (notable event)?

Options

  • AMultiply the risk score of a detection by how many times it has run.
  • BLeverage the scheduling priority of the detection to know what's most critical.
  • CAdd risk scores for associated objects within a network.
  • DTake into account the priority assigned to the asset/identity as well as the severity value assigned

How the community answered

(21 responses)
  • A
    5% (1)
  • B
    10% (2)
  • C
    5% (1)
  • D
    81% (17)

Explanation

In Splunk Enterprise Security, the default method for determining the urgency of a notable event considers both the priority of the asset or identity involved and the severity value assigned to the finding. This ensures that critical assets with high-severity events are prioritized appropriately for analyst attention.

Topics

#notable events#urgency calculation#asset priority#severity

Community Discussion

No community discussion yet for this question.

Full SPLK-5002 Practice