Question 16

A new playbook needs to be developed for automated phishing analysis and response. Configured in SOAR are integrations with Splunk Enterprise Security and actions from assets that pull in user- reported emails, perform automated threat analysis, add blocks on the proxy, and an EDR vendor to take various actions. Which would be the best workflow for the new playbook?
  • Question 17

    During an incident, a correlation search generates several notable events related to failed logins. The engineer notices the events are from test accounts.
    Whatshould be done to address this?
  • Question 18

    Utilizing a Standard Operating Procedure (SOP) is an effective way to ensure that analysts are responding to generated findings in a consistent and analytical manner. Where is the best place within the Notable Adaptive Response Action to include a link to an SOP?
  • Question 19

    What methods can improve Splunk's indexing performance?(Choosetwo)
  • Question 20

    Which syntax is correct to create two new rows on an existing threat intelligence collection?