CCOA • Practice Exam 4 — 20 Questions
Free CCOA practice exam 4 — 20 questions with explanations. No signup required.
You are configuring a Splunk Enterprise Security (ES) Correlation Search to detect potential brute-force activity. You need to ensure the search generates a notable event only when the threshold of 10 failed logins occurs within a 5-minute window for a specific user. Which Correlation Search attribute should be modified?
Choose an answer to begin — your selection is scored in the full session.
20 questions · instant feedback and full explanations after every question.