nerdexam
Splunk

SPLK-5001 · Question #11

Splunk Enterprise Security has numerous frameworks to create correlations, integrate threat intelligence, and provide a workflow for investigations. Which framework raises the threat profile of…

The correct answer is B. Risk Framework. Option B (Risk Framework) is correct because it is specifically designed to aggregate suspicious activities into a cumulative "risk score" for individuals or assets, raising their threat profile over time - allowing analysts to identify users or devices exhibiting an unusual…

Threat Detection and Alerting

Question

Splunk Enterprise Security has numerous frameworks to create correlations, integrate threat intelligence, and provide a workflow for investigations. Which framework raises the threat profile of individuals or assets to allow identification of people or devices that perform an unusual amount of suspicious activities?

Options

  • AThreat Intelligence Framework
  • BRisk Framework
  • CNotable Event Framework
  • DAsset and Identity Framework

How the community answered

(39 responses)
  • A
    3% (1)
  • B
    95% (37)
  • C
    3% (1)

Explanation

Option B (Risk Framework) is correct because it is specifically designed to aggregate suspicious activities into a cumulative "risk score" for individuals or assets, raising their threat profile over time - allowing analysts to identify users or devices exhibiting an unusual volume of suspicious behavior, even if no single event crosses an alert threshold.

Why the distractors are wrong:

  • A (Threat Intelligence Framework): Focuses on ingesting, correlating, and acting on external threat intel feeds (IPs, domains, hashes) - not scoring internal entities.
  • C (Notable Event Framework): Creates and manages notable events (alerts) for individual triggered correlations, but doesn't accumulate a threat profile across multiple events over time.
  • D (Asset and Identity Framework): Enriches events with contextual data about assets and identities (ownership, priority, location) - it provides metadata, not behavioral risk scoring.

Memory tip: Think of the Risk Framework as a "strike counter" - each suspicious activity adds strikes to a person or device's record until they're flagged as high-risk. The word "raises the threat profile" in the question is the direct giveaway, since risk scores are what get raised.

Topics

#Risk Framework#RBA#Enterprise Security#risk scoring

Community Discussion

No community discussion yet for this question.

Full SPLK-5001 Practice