SPLK-5001 · Question #76
Which pre-packaged app delivers security content and detections on a regular, ongoing basis for Enterprise Security and SOAR?
The correct answer is B. ESCU. ESCU (Enterprise Security Content Update) is the pre-packaged Splunk app specifically designed to deliver curated security content - including correlation searches, detections, and threat intelligence - on a continuous, subscription-based cadence directly into Enterprise…
Question
Which pre-packaged app delivers security content and detections on a regular, ongoing basis for Enterprise Security and SOAR?
Options
- ASSE
- BESCU
- CThreat Hunting
- DInfoSec
How the community answered
(28 responses)- A4% (1)
- B86% (24)
- C4% (1)
- D7% (2)
Explanation
ESCU (Enterprise Security Content Update) is the pre-packaged Splunk app specifically designed to deliver curated security content - including correlation searches, detections, and threat intelligence - on a continuous, subscription-based cadence directly into Enterprise Security (ES) and SOAR environments.
Why the distractors are wrong:
- A. SSE (Splunk Security Essentials) is a free exploration app for discovering and learning about security content, but it does not push ongoing production detections into ES/SOAR.
- C. Threat Hunting is a workflow and methodology within ES, not a content delivery app.
- D. InfoSec is not a recognized Splunk product in this context - it's a general industry term, not an app.
Memory tip: Think of ESCU as a "subscription service" - the U stands for Update, reminding you it continuously updates your security content. If it has "Update" in the name, it's the one doing the delivering.
Topics
Community Discussion
No community discussion yet for this question.