SPLK-1001 Exam QuestionsBrowse all questions from this exam

SPLK-1001 Exam - Question 204


A SOC manager is complaining that a scheduled alert for failed login attempts triggered 150 emails. They still want to be alerted of failed logins via email, but they want less volume of alerts. Which of the following would resolve this for the SOC manager?

Show Answer
Correct Answer: AC

To reduce the volume of alert emails for failed login attempts, the trigger can be adjusted from 'For each result' to 'Once'. This change will ensure that instead of sending an email for each failed login attempt, the alert will only trigger a single email, consolidating the information into one alert rather than multiple.

Discussion

6 comments
Sign in to comment
ncsupilotOption: C
Oct 11, 2022

C is correct. You change the alert frequency.

SlyLampOption: C
Sep 8, 2022

C is the correct answer

nicksssOption: C
Oct 7, 2022

Running more frequently would not decrease the emails. C is the correct answer.

mialuxOption: C
Nov 10, 2022

c is correct

b0d4564Option: C
Feb 21, 2024

fck u its C

73c1843Option: C
May 29, 2024

100% Its "C"