Question 36

Which features of Splunk are crucial for tuning correlation searches? (Choose three)
  • Question 37

    Which of the following actions will allow access to a list of alert actions via the API?
  • Question 38

    How does Mission Control decipher which response template to assign to findings?
  • Question 39

    Lookups append fields from an external source to events based on the values of fields that are already present in those events. What are the four supported lookup types?
  • Question 40

    Which of the following should an engineer do as they evaluate their Threat Detection and Incident Response lifecycle?