SPLK-5001 · Question #11
Splunk Enterprise Security has numerous frameworks to create correlations, integrate threat intelligence, and provide a workflow for investigations. Which framework raises the threat profile of…
The correct answer is B. Risk Framework. Option B (Risk Framework) is correct because it is specifically designed to aggregate suspicious activities into a cumulative "risk score" for individuals or assets, raising their threat profile over time - allowing analysts to identify users or devices exhibiting an unusual…
Question
Splunk Enterprise Security has numerous frameworks to create correlations, integrate threat intelligence, and provide a workflow for investigations. Which framework raises the threat profile of individuals or assets to allow identification of people or devices that perform an unusual amount of suspicious activities?
Options
- AThreat Intelligence Framework
- BRisk Framework
- CNotable Event Framework
- DAsset and Identity Framework
How the community answered
(39 responses)- A3% (1)
- B95% (37)
- C3% (1)
Explanation
Option B (Risk Framework) is correct because it is specifically designed to aggregate suspicious activities into a cumulative "risk score" for individuals or assets, raising their threat profile over time - allowing analysts to identify users or devices exhibiting an unusual volume of suspicious behavior, even if no single event crosses an alert threshold.
Why the distractors are wrong:
- A (Threat Intelligence Framework): Focuses on ingesting, correlating, and acting on external threat intel feeds (IPs, domains, hashes) - not scoring internal entities.
- C (Notable Event Framework): Creates and manages notable events (alerts) for individual triggered correlations, but doesn't accumulate a threat profile across multiple events over time.
- D (Asset and Identity Framework): Enriches events with contextual data about assets and identities (ownership, priority, location) - it provides metadata, not behavioral risk scoring.
Memory tip: Think of the Risk Framework as a "strike counter" - each suspicious activity adds strikes to a person or device's record until they're flagged as high-risk. The word "raises the threat profile" in the question is the direct giveaway, since risk scores are what get raised.
Topics
Community Discussion
No community discussion yet for this question.