Question 6

How can an engineer verify if results will return for a potential detection based on historical events within the organization?
  • Question 7

    A detection engineer is using a threat defense informed strategy to define use cases. Which Splunk app would best facilitate their use case development process by cross referencing detections with the MITRE ATT&CK Framework?
  • Question 8

    The following SPL is designed to report on a certain SOC metric. Which metric is the most likely topic for this report?
  • Question 9

    The Director of Security would like to understand the operational efficiency of the SOC analysts at a high level. What is a metric that can be used to determine their efficiency?
  • Question 10

    What is the purpose of leveraging REST APIs in a Splunk automation workflow?