nerdexam
Splunk

SPLK-2003 · Question #120

Which of the following actions will store a compressed, secure version of an email attachment with suspected malware for future analysis?

The correct answer is D. Use the Upload action of the Secure Store app to store the file in the database.. To securely store a compressed version of an email attachment suspected of containing malware for future analysis, the most effective approach within Splunk SOAR is to use the Upload action of the Secure Store app. This app is specifically designed to handle sensitive or potentia

Automating Tasks

Question

Which of the following actions will store a compressed, secure version of an email attachment with suspected malware for future analysis?

Options

  • ACopy/paste the attachment into a note.
  • BAdd a link to the file in a new artifact.
  • CUse the Files tab on the Investigation page to upload the attachment.
  • DUse the Upload action of the Secure Store app to store the file in the database.

How the community answered

(39 responses)
  • A
    3% (1)
  • B
    8% (3)
  • C
    15% (6)
  • D
    74% (29)

Explanation

To securely store a compressed version of an email attachment suspected of containing malware for future analysis, the most effective approach within Splunk SOAR is to use the Upload action of the Secure Store app. This app is specifically designed to handle sensitive or potentially dangerous files by securely storing them within the SOAR database, allowing for controlled access and analysis at a later time. This method ensures that the file is not only safely contained but also available for future forensic or investigative purposes without risking exposure to the

Topics

#Secure Store#file storage#malware handling#evidence management

Community Discussion

No community discussion yet for this question.

Full SPLK-2003 Practice