최신Splunk Certified Cybersecurity Defense Engineer - SPLK-5002무료샘플문제
What is the primary purpose of correlation searches in Splunk?
A company wants to implement risk-based detection for privileged account activities. What should they configure first?
In a contextualization playbook, a URL is transmitted to a sandbox for examination and disposition recommendation. What underlying HTTP method is used to transmit this data to the sandbox?
An engineer is examining a correlation search as a part of a detection review, and sees that it is configured in the following fashion:

Which of the following is true about this configuration?
How can you incorporate additional context into notable events generated by correlation searches?
A corporate laptop was disconnected from the internet Friday at 5PM local time. While offline, the user unknowingly opened a malicious file. The laptop came back online the following Monday morning, 9AM local time. The current detection has a 15 minute lookback period. How can the detection be tuned to account for this scenario?