SPLK-5002 · Question #51
What is Enterprise Security's default way of determining the urgency of a finding (notable event)?
The correct answer is D. Take into account the priority assigned to the asset/identity as well as the severity value assigned. In Splunk Enterprise Security, the default method for determining the urgency of a notable event considers both the priority of the asset or identity involved and the severity value assigned to the finding. This ensures that critical assets with high-severity events are…
Question
What is Enterprise Security's default way of determining the urgency of a finding (notable event)?
Options
- AMultiply the risk score of a detection by how many times it has run.
- BLeverage the scheduling priority of the detection to know what's most critical.
- CAdd risk scores for associated objects within a network.
- DTake into account the priority assigned to the asset/identity as well as the severity value assigned
How the community answered
(21 responses)- A5% (1)
- B10% (2)
- C5% (1)
- D81% (17)
Explanation
In Splunk Enterprise Security, the default method for determining the urgency of a notable event considers both the priority of the asset or identity involved and the severity value assigned to the finding. This ensures that critical assets with high-severity events are prioritized appropriately for analyst attention.
Topics
Community Discussion
No community discussion yet for this question.