nerdexam
Splunk

SPLK-5001 · Question #110

While investigating a finding in Splunk, an analyst manually searches for threat intelligence matches and adds them to a list if they come back as malicious. Then, they send a request to contain the…

The correct answer is B. A SOAR playbook triggered by the detection. A Splunk SOAR playbook can ingest the notable event, automatically query threat‑intel, update lists for malicious indicators, and execute containment actions on the affected host - all in one end‑to‑end, fully automated workflow.

Incident Investigation and Response

Question

While investigating a finding in Splunk, an analyst manually searches for threat intelligence matches and adds them to a list if they come back as malicious. Then, they send a request to contain the compromised host. What would be the best solution to fully automate this process?

Options

  • AAn intelligence response action.
  • BA SOAR playbook triggered by the detection.
  • CDocument those steps in the team's runbook.
  • DA model-assisted threat hunt.

How the community answered

(19 responses)
  • A
    11% (2)
  • B
    68% (13)
  • C
    5% (1)
  • D
    16% (3)

Explanation

A Splunk SOAR playbook can ingest the notable event, automatically query threat‑intel, update lists for malicious indicators, and execute containment actions on the affected host - all in one end‑to‑end, fully automated workflow.

Topics

#SOAR playbook#automation#threat intelligence#host containment

Community Discussion

No community discussion yet for this question.

Full SPLK-5001 Practice