Q: 14
A Risk Notable Event has been triggered in Splunk Enterprise Security, an analyst investigates the
alert, and determines it is a false positive. What metric would be used to define the time between
alert creation and close of the event?
Options
Discussion
A , MTTR measures from alert creation to close. MTTA is a trap here, since that's about acknowledgment not full closure.
I’d say A since MTTR covers the full time from alert to closure, not just initial response. The others don’t measure that end-to-end window as directly. Pretty sure about this but curious if anyone disagrees.
A makes sense here since MTTR is about closing out incidents, whether they're real or false positives. B, C, and D wouldn't fit because they track totally different parts of the timeline. I think MTTR fits best for alert creation to closure, but if the process involved initial triage only (not full resolve), sometimes folks mix up with MTTA. Anyone else seen exam items where that's caused confusion?
A , saw a similar one in the official practice. Official docs and blueprints help nail these metric questions.
Be respectful. No spam.
Question 14 of 15