SPLK-5001 · Question #63
Which of the following Splunk Enterprise Security features allows industry frameworks such as CIS Critical Security Controls, MITRE ATT&CK, and the Lockheed Martin Cyber Kill Chain?to be mapped to…
The correct answer is A. Annotations. Annotations in Splunk Enterprise Security serve as metadata tags that link Correlation Search results to industry frameworks like MITRE ATT&CK, CIS Controls, and the Cyber Kill Chain - enabling security teams to contextualize alerts within standardized threat models directly on…
Question
Which of the following Splunk Enterprise Security features allows industry frameworks such as CIS Critical Security Controls, MITRE ATT&CK, and the Lockheed Martin Cyber Kill Chain?to be mapped to Correlation Search results?
Options
- AAnnotations
- BPlaybooks
- CComments
- DEnrichments
How the community answered
(60 responses)- A88% (53)
- B7% (4)
- C2% (1)
- D3% (2)
Explanation
Annotations in Splunk Enterprise Security serve as metadata tags that link Correlation Search results to industry frameworks like MITRE ATT&CK, CIS Controls, and the Cyber Kill Chain - enabling security teams to contextualize alerts within standardized threat models directly on Notable Events.
Why the distractors are wrong:
- B. Playbooks are automated response workflows (SOAR actions) triggered by alerts - they execute tasks, not map frameworks.
- C. Comments are free-text notes added by analysts to Notable Events for collaboration - they have no structured framework mapping capability.
- D. Enrichments add contextual data to events (e.g., threat intel lookups, asset/identity info) - they augment data but don't map to security frameworks.
Memory tip: Think "Annotations = Attribution" - they annotate a detection with its framework attribution (ATT&CK technique, Kill Chain phase, etc.), essentially answering "what does this alert mean in the context of known attack frameworks?"
Topics
Community Discussion
No community discussion yet for this question.