Question 6
How can an engineer verify if results will return for a potential detection based on historical events within the organization?
Question 7
A detection engineer is using a threat defense informed strategy to define use cases. Which Splunk app would best facilitate their use case development process by cross referencing detections with the MITRE ATT&CK Framework?
Question 8
The following SPL is designed to report on a certain SOC metric. Which metric is the most likely topic for this report?


Question 9
The Director of Security would like to understand the operational efficiency of the SOC analysts at a high level. What is a metric that can be used to determine their efficiency?
Question 10
What is the purpose of leveraging REST APIs in a Splunk automation workflow?
