Big 11.11 Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Splunk Enterprise Security Certified Admin Exam SPLK-3001 Question # 22 Topic 3 Discussion

Splunk Enterprise Security Certified Admin Exam SPLK-3001 Question # 22 Topic 3 Discussion

SPLK-3001 Exam Topic 3 Question 22 Discussion:
Question #: 22
Topic #: 3

The Brute Force Access Behavior Detected correlation search is enabled, and is generating many false positives. Assuming the input data has already been validated. How can the correlation search be made less sensitive?


A.

Edit the search and modify the notable event status field to make the notable events less urgent.


B.

Edit the search, look for where or xswhere statements, and after the threshold value being compared to make it less common match.


C.

Edit the search, look for where or xswhere statements, and alter the threshold value being compared to make it a more common match.


D.

Modify the urgency table for this correlation search and add a new severity level to make notable events from this search less urgent.


Get Premium SPLK-3001 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.