Splunk
SPLK-5001 · Question #113
Splunk detections can be mapped to their appropriate MITRE ATT&CK® Techniques using which feature?
The correct answer is C. Annotations. In Splunk Enterprise Security, correlation searches and other detections include annotation fields where you map each detection to its corresponding MITRE ATT&CK® tactic and technique IDs. These Annotations are what drive the ATT&CK mapping in dashboards and reports.
Threat Detection and Alerting
Question
Splunk detections can be mapped to their appropriate MITRE ATT&CK® Techniques using which feature?
Options
- AContext
- BThreat Intelligence
- CAnnotations
- DCorrelations
How the community answered
(41 responses)- A2% (1)
- B7% (3)
- C88% (36)
- D2% (1)
Explanation
In Splunk Enterprise Security, correlation searches and other detections include annotation fields where you map each detection to its corresponding MITRE ATT&CK® tactic and technique IDs. These Annotations are what drive the ATT&CK mapping in dashboards and reports.
Topics
#MITRE ATT&CK#annotations#detection mapping#Enterprise Security
Community Discussion
No community discussion yet for this question.