Question 36

Which of the following use cases is best suited to be a Splunk SOAR Playbook?
A Forming hypothesis for Threat Hunting
B. Visualizing complex datasets.
C. Creating persistent field extractions.
D. Taking containment action on a compromised host

Question 37

Rotating the encryption keys used by a public web server after a security incident is most closely linked to which security concept?
  • Question 38

    A user wants to view only the use cases for which the Splunk instance has all of the supporting source types to implement. In Splunk Security Essentials, what operation needs to happen first?
  • Question 39

    Which pre-packaged app delivers security content and detections on a regular, ongoing basis for Enterprise Security and SOAR?
  • Question 40

    What feature of Splunk Security Essentials (SSE) allows an analyst to see a listing of current on- boarded data sources in Splunk so they can view content based on available data?