SPLK-5003 無料問題集「Splunk Certified Cybersecurity Defense Architect」
A corporate cybersecurity team operating within the retail sector finds that its existing cyber threat intelligence (CTI) feeds are noisy and lack relevance to the environment. What type of CTI provider feed, shared among other retail organizations, should they consider to improve their CTI effectiveness?
正解:B
解答を投票する
解説: (JPNTest メンバーにのみ表示されます)
A threat hunter is looking for suspicious login activity across multiple different authentication systems and cloud providers. Today, the threat hunter has to query multiple different data sources with unique logic to gather basic information about authentication events. What method provides a simple way to standardize data formats, and look for common activity across different sources?
正解:B
解答を投票する
解説: (JPNTest メンバーにのみ表示されます)
An organization has decided to implement a new endpoint security product. The CISO has concerns about the rollout due to the nature of the varied endpoint builds and installed applications. After initial testing in lab has shown no issues, what next step should the architect perform to ensure the success of their rollout?
正解:D
解答を投票する
解説: (JPNTest メンバーにのみ表示されます)