Question 21
Which features of Splunk are crucial for tuning correlation searches? (Choose three)
Question 22
Which of the following detections would use a high count of events with Windows Event Code 4740 grouped by a user to determine suspicious behavior?
Question 23
When creating a detection that searches user activity across CIM-compliant data, which CIM field should be reviewed to ensure that data is aggregated appropriately?
Question 24
What are key benefits of automating responses using SOAR?(Choosethree)
Question 25
The below search is used to tabulate the Risk Score by Entity. What is incorrect about this search?


