SPLK-3001 Exam QuestionsBrowse all questions from this exam

SPLK-3001 Exam - Question 54


The Brute Force Access Behavior Detected correlation search is enabled, and is generating many false positives. Assuming the input data has already been validated.

How can the correlation search be made less sensitive?

Show Answer
Correct Answer: B

To make a correlation search less sensitive, you need to adjust the criteria that trigger alerts so that fewer false positives occur. This can be done by editing the search and modifying the where or xswhere statements to alter the threshold value. By increasing the threshold value, you make it less likely for the conditions to be met, thereby reducing the number of false positives. Making it less common means setting the threshold to a higher number or less frequently occurring condition, which aligns with option B.

Discussion

1 comment
Sign in to comment
tjolesOption: B
May 17, 2023

Answer is B. there is a typo(should be alter)