Question 21

Which features of Splunk are crucial for tuning correlation searches? (Choose three)
  • Question 22

    Which of the following detections would use a high count of events with Windows Event Code 4740 grouped by a user to determine suspicious behavior?
  • Question 23

    When creating a detection that searches user activity across CIM-compliant data, which CIM field should be reviewed to ensure that data is aggregated appropriately?
  • Question 24

    What are key benefits of automating responses using SOAR?(Choosethree)
  • Question 25

    The below search is used to tabulate the Risk Score by Entity. What is incorrect about this search?