nerdexam
Splunk

SPLK-5001 · Question #10

A successful Continuous Monitoring initiative involves the entire organization. When an analyst discovers the need for more context or additional information, perhaps from additional data sources or…

The correct answer is C. Security Engineer. Security Engineers are the appropriate escalation point because they own the technical implementation layer - including SIEM tuning, onboarding new log sources, and modifying correlation rules. When an analyst identifies a gap in visibility or detection logic, the fix requires…

Incident Investigation and Response

Question

A successful Continuous Monitoring initiative involves the entire organization. When an analyst discovers the need for more context or additional information, perhaps from additional data sources or altered correlation rules, to what role would this request generally escalate?

Options

  • ASOC Manager
  • BSecurity Analyst
  • CSecurity Engineer
  • DSecurity Architect

How the community answered

(33 responses)
  • A
    3% (1)
  • B
    6% (2)
  • C
    88% (29)
  • D
    3% (1)

Explanation

Security Engineers are the appropriate escalation point because they own the technical implementation layer - including SIEM tuning, onboarding new log sources, and modifying correlation rules. When an analyst identifies a gap in visibility or detection logic, the fix requires hands-on engineering work that falls squarely in the Engineer's domain.

A (SOC Manager) is wrong because managers handle people, priorities, and budgets - not technical tool configuration. Escalating a correlation rule change to a manager would skip the technical layer entirely.

B (Security Analyst) is wrong because that's the same role raising the concern - peers don't resolve each other's data source gaps; this needs someone with implementation authority.

D (Security Architect) is wrong because architects operate at the strategic/design level (selecting platforms, defining frameworks) and are not responsible for day-to-day tuning of operational tools.

Memory tip: Think of it as a ladder - Analyst detects the gap, Engineer fixes the gap, Architect designs the system, Manager resources the team. When something needs to be built or changed, it goes to the Engineer.

Topics

#SOC roles#continuous monitoring#escalation#security engineer

Community Discussion

No community discussion yet for this question.

Full SPLK-5001 Practice