SPLK-5001 · Question #62
Which Enterprise Security framework provides a mechanism for running preconfigured actions within the Splunk platform or integrating with external applications?
The correct answer is D. Adaptive Response. Adaptive Response (D) is correct because it is the Splunk Enterprise Security framework specifically designed to trigger preconfigured actions - called Adaptive Response Actions - either within Splunk itself (e.g., running a search, creating a notable event) or by integrating…
Question
Which Enterprise Security framework provides a mechanism for running preconfigured actions within the Splunk platform or integrating with external applications?
Options
- AAsset and Identity
- BNotable Event
- CThreat Intelligence
- DAdaptive Response
How the community answered
(40 responses)- A8% (3)
- B3% (1)
- C3% (1)
- D88% (35)
Explanation
Adaptive Response (D) is correct because it is the Splunk Enterprise Security framework specifically designed to trigger preconfigured actions - called Adaptive Response Actions - either within Splunk itself (e.g., running a search, creating a notable event) or by integrating with external tools like ticketing systems, firewalls, or SOAR platforms.
- A (Asset and Identity) is wrong - this framework manages inventory of assets and user identities to enrich events with context, not to trigger actions.
- B (Notable Event) is wrong - Notable Events are the output/findings generated by correlation searches; they represent alerts, not an action-execution mechanism.
- C (Threat Intelligence) is wrong - this framework ingests and manages IOC data (IPs, domains, hashes) to correlate against, not to run actions.
Memory tip: Think of "Adaptive Response" as Splunk's way of responding - it adapts to a threat by taking action. The word "response" directly signals action-taking, which distinguishes it from the other frameworks that are about data enrichment (Asset/Identity, Threat Intel) or alert representation (Notable Events).
Topics
Community Discussion
No community discussion yet for this question.