nerdexam
Splunk

SPLK-5001 · Question #113

Splunk detections can be mapped to their appropriate MITRE ATT&CK® Techniques using which feature?

The correct answer is C. Annotations. In Splunk Enterprise Security, correlation searches and other detections include annotation fields where you map each detection to its corresponding MITRE ATT&CK® tactic and technique IDs. These Annotations are what drive the ATT&CK mapping in dashboards and reports.

Threat Detection and Alerting

Question

Splunk detections can be mapped to their appropriate MITRE ATT&CK® Techniques using which feature?

Options

  • AContext
  • BThreat Intelligence
  • CAnnotations
  • DCorrelations

How the community answered

(41 responses)
  • A
    2% (1)
  • B
    7% (3)
  • C
    88% (36)
  • D
    2% (1)

Explanation

In Splunk Enterprise Security, correlation searches and other detections include annotation fields where you map each detection to its corresponding MITRE ATT&CK® tactic and technique IDs. These Annotations are what drive the ATT&CK mapping in dashboards and reports.

Topics

#MITRE ATT&CK#annotations#detection mapping#Enterprise Security

Community Discussion

No community discussion yet for this question.

Full SPLK-5001 Practice