SPLK-3001 Exam QuestionsBrowse all questions from this exam

SPLK-3001 Exam - Question 30


Which of the following actions would not reduce the number of false positives from a correlation search?

Show Answer
Correct Answer: A

Reducing the severity would not reduce the number of false positives from a correlation search. Severity levels are used to indicate the importance or priority of events or alerts, but they do not affect the actual detection or accuracy of the correlation search. Therefore, changing the severity level will not impact the rate of false positives.

Discussion

9 comments
Sign in to comment
okseyOption: B
Sep 24, 2020

A is correct not B

andy73Option: A
Dec 1, 2021

A is correct

NtaniOption: A
Feb 11, 2023

A is correct

okseyOption: B
Sep 21, 2020

I am not sure but I think B will do the job

1qaz2wsx
Sep 25, 2021

"not reduce"

_ademOption: A
Oct 4, 2021

A is correct

noysherer
Dec 28, 2021

Can someone please explain this?

qtygbapjpesdayazkoOption: C
Apr 17, 2023

C. Increasing the throttling window: This option may help reduce false positives. The throttling window determines how long related events are grouped together. If the window is too short, unrelated events may be grouped together, generating false positives. If the window is too long, legitimate events may be excluded from the group. Increasing the window may allow more legitimate events to be grouped together, reducing the number of false positives.

RIchardMatosOption: C
Jun 13, 2023

Increasing the throttling window: Throttling window defines the time period during which events are considered for correlation. Increasing the throttling window allows for a broader time range of events to be considered, which can help in better identifying true correlations and reducing false positives.

RIchardMatos
Jun 14, 2023

Sorry, correcting here option A is correct : A. Reducing the severity. Reducing the severity would not directly impact the number of false positives in a correlation search. Severity is typically used to assign a level of importance or priority to events or alerts, but it doesn't affect the accuracy or false positive rate of the correlation search itself.

c2mp2Option: A
Feb 8, 2024

A is correct