nerdexam
Splunk

SPLK-2003 · Question #37

What are the differences between cases and events?

The correct answer is C. Cases: contain a collection of containers.. In Splunk SOAR, an event is a security occurrence that may require a response. It is ingested from a third-party source and can be labeled to group related events together. The default label for containers is "Events," which signifies potential threats. A case, on the other hand,

Splunk SOAR Environment

Question

What are the differences between cases and events?

Options

  • ACase: potential threats.
  • BCases: only include high-level incident artifacts.
  • CCases: contain a collection of containers.
  • DCases: incidents with a known violation and a plan for correction.

How the community answered

(32 responses)
  • A
    3% (1)
  • C
    94% (30)
  • D
    3% (1)

Explanation

In Splunk SOAR, an event is a security occurrence that may require a response. It is ingested from a third-party source and can be labeled to group related events together. The default label for containers is "Events," which signifies potential threats. A case, on the other hand, is a container that holds several containers, consolidating multiple events into one logical management unit. Cases can include artifacts and external evidence such as screen captures, analyst notes, and event data from third-party products. They are used to manage and analyze investigation data tied to specific security events and incidents, providing a structured approach to incident response.

Topics

#cases#events#containers#case management

Community Discussion

No community discussion yet for this question.

Full SPLK-2003 Practice