nerdexam
Splunk

SPLK-5001 · Question #100

Which Splunk Enterprise Security framework provides a way to identify incidents from events and then manage the ownership, triage process, and state of those incidents?

The correct answer is A. Investigation Management. The Investigation Management framework in Splunk ES takes notable events and creates incidents, then provides the workflows and tools to assign ownership, track triage progress, and manage incident states from open through resolution.

Incident Investigation and Response

Question

Which Splunk Enterprise Security framework provides a way to identify incidents from events and then manage the ownership, triage process, and state of those incidents?

Options

  • AInvestigation Management
  • BNotable Event
  • CAsset and Identity
  • DAdaptive Response

How the community answered

(27 responses)
  • A
    85% (23)
  • B
    7% (2)
  • C
    4% (1)
  • D
    4% (1)

Explanation

The Investigation Management framework in Splunk ES takes notable events and creates incidents, then provides the workflows and tools to assign ownership, track triage progress, and manage incident states from open through resolution.

Topics

#Notable Event#incident management#Splunk ES#SOC workflow

Community Discussion

No community discussion yet for this question.

Full SPLK-5001 Practice