SPLK-5003試験無料問題集「Splunk Certified Cybersecurity Defense Architect 認定」
A global enterprise is experiencing severe performance issues on their Splunk Enterprise Security Search Head due to an overwhelming number of distinct Asset and Identity lookups being performed simultaneously. What is the BEST architectural recommendation to resolve this performance issue?
正解:A
解答を投票する
解説: (GoShiken メンバーにのみ表示されます)
A threat hunter is looking for suspicious login activity across multiple different authentication systems and cloud providers. Today, the threat hunter has to query multiple different data sources with unique logic to gather basic information about authentication events. What method provides a simple way to standardize data formats, and look for common activity across different sources?
正解:B
解答を投票する
解説: (GoShiken メンバーにのみ表示されます)
Kevin is a SOC analyst working with the SRE team to investigate a report of slow responses from a customer-facing web application. While looking at load balancer and WAF logs, Kevin has discovered that one of the web servers hosting the application has gone offline. He does not see any alerts in the WAF or from the endpoint detection and response agent running on the web server. As part of triaging this incident, what should they do next? (Choose all that apply.)
正解:A,C
解答を投票する
解説: (GoShiken メンバーにのみ表示されます)
The growing rate of cyber attacks has led many countries to adopt laws and regulations pertaining to the collection, handling, and security of their citizens' private information regardless of where it is stored. Which of the following terms best describes these laws?
正解:A
解答を投票する
解説: (GoShiken メンバーにのみ表示されます)
A cybersecurity team is looking to leverage DevSecOps best practices. They want to test new security policies with a small subset of users while monitoring for unusual access patterns or failures. Which of the following techniques will support this? (Choose all that apply.)
正解:B,D
解答を投票する
解説: (GoShiken メンバーにのみ表示されます)