nerdexam
Splunk

SPLK-2003 · Question #22

When analyzing events a working on a case, significant items can be marked as evidence. Where can ail of a case's evidence items be viewed together?

The correct answer is C. Investigation page Evidence tab. In Splunk SOAR, when working on a case and analyzing events, items marked as significant evidence are aggregated for review. These evidence items can be collectively viewed on the Investigation page under the Evidence tab. This centralized view allows analysts to easily access…

Splunk SOAR Environment

Question

When analyzing events a working on a case, significant items can be marked as evidence. Where can ail of a case's evidence items be viewed together?

Options

  • AWorkbook page Evidence tab.
  • BEvidence report.
  • CInvestigation page Evidence tab.
  • DAt the bottom of the Investigation page widget panel.

How the community answered

(16 responses)
  • A
    6% (1)
  • C
    94% (15)

Explanation

In Splunk SOAR, when working on a case and analyzing events, items marked as significant evidence are aggregated for review. These evidence items can be collectively viewed on the Investigation page under the Evidence tab. This centralized view allows analysts to easily access and review all marked evidence related to a case, facilitating a streamlined analysis process and ensuring that key information is readily available for investigation and decision-making.

Topics

#case management#evidence#Investigation page#workbook

Community Discussion

No community discussion yet for this question.

Full SPLK-2003 Practice