Question 66

A detection engineer is using a threat defense informed strategy to define use cases. Which Splunk app would best facilitate their use case development process by cross referencing detections with the MITRE ATT & CK Framework?
  • Question 67

    The SOC Manager requested a better method to standardize the list of tasks that analysts follow when they evaluate events or cases. Which Splunk SOAR feature allows the creation of SOPs based on criteria like the type of event or attack vector?
  • Question 68

    Which of the following is a reason to utilize an index-based search (index=...) over a data model search (| tstats...) in a detection?
  • Question 69

    What cardinality of data should be used in an indexed field to optimize and speed up searches?
  • Question 70

    Once an engineer has determined that a new detection will fire, what is the next priority for that detection?