Question 56
While investigating a finding in Splunk, an analyst manually searches for threat intelligence matches and adds them to a list if they come back as malicious. Then, they send a request to contain the compromised host.
What would be the best solution to fully automate this process?
What would be the best solution to fully automate this process?
Question 57
Which Splunk Enterprise Security dashboard displays authentication and access-related data?
Question 58
Which of the following Splunk Enterprise Security features allows industry frameworks such as CIS Critical Security Controls, MITRE ATT&CK, and the Lockheed Martin Cyber Kill Chain to be mapped to Correlation Search results?
Question 59
A security analyst wants to enrich public IP addresses found within logs with the Autonomous System Number and owner of the address. What Splunk feature would enable the analyst to do this?
Question 60
In SPL, streaming commands operate on each individual event. There are two types of streaming commands: distributableand centralized. Which of the following statements is true about search efficiency using streaming commands?
