Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Splunk SPLK-5002 Exam - Topic 1 Question 28 Discussion

What is one method used in ESCU content to calculate a risk score when creating a detection that uses the Risk Analysis adaptive response action?
A) Risk Score = (Impact Confidence / 100)
B) Risk Score = (Risk Object Severity Confidence / 100)
C) Risk Score = (Risk Object Priority Confidence / 100)
D) Risk Score = (Impact Priority / 100)

Splunk SPLK-5002 Exam - Topic 1 Question 28 Discussion

Actual exam question for Splunk's SPLK-5002 exam
Question #: 28
Topic #: 1
[All SPLK-5002 Questions]

What is one method used in ESCU content to calculate a risk score when creating a detection that uses the Risk Analysis adaptive response action?

Show Suggested Answer Hide Answer
Suggested Answer: A

A common ESCU methodology calculates risk as:

Risk Score = Impact Confidence / 100

Impact represents the potential significance or consequence of the detected behavior, while confidence represents how strongly the analytic supports the conclusion that the activity is security-relevant. Dividing by 100 normalizes the confidence percentage when combining the two values.

For example, if a detection has an impact value of 80 and confidence of 75%, the resulting score is:

80 75 / 100 = 60

This methodology prevents a high-impact but low-confidence analytic from automatically producing the same risk contribution as a high-impact, high-confidence detection. It therefore supports Risk-Based Alerting by allowing individual detections to contribute proportional evidence to a user, host, or other risk object.

Risk-object priority or severity can still influence downstream prioritization through contextual enrichment and Risk Factors, but those concepts are distinct from this ESCU risk-score calculation. The supplied Cybersecurity Defense Engineer material separately reinforces the role of risk scores, Risk Factors, and contextual prioritization in Enterprise Security.

Study Guide topics: ESCU, Risk Analysis adaptive response action, risk score, impact, confidence, Risk-Based Alerting, risk objects.


Contribute your Thoughts:

0/2000 characters

Currently there are no comments in this discussion, be the first to comment!


Save Cancel