nerdexam
Splunk

SPLK-5001 · Question #76

Which pre-packaged app delivers security content and detections on a regular, ongoing basis for Enterprise Security and SOAR?

The correct answer is B. ESCU. ESCU (Enterprise Security Content Update) is the pre-packaged Splunk app specifically designed to deliver curated security content - including correlation searches, detections, and threat intelligence - on a continuous, subscription-based cadence directly into Enterprise…

Threat Detection and Alerting

Question

Which pre-packaged app delivers security content and detections on a regular, ongoing basis for Enterprise Security and SOAR?

Options

  • ASSE
  • BESCU
  • CThreat Hunting
  • DInfoSec

How the community answered

(28 responses)
  • A
    4% (1)
  • B
    86% (24)
  • C
    4% (1)
  • D
    7% (2)

Explanation

ESCU (Enterprise Security Content Update) is the pre-packaged Splunk app specifically designed to deliver curated security content - including correlation searches, detections, and threat intelligence - on a continuous, subscription-based cadence directly into Enterprise Security (ES) and SOAR environments.

Why the distractors are wrong:

  • A. SSE (Splunk Security Essentials) is a free exploration app for discovering and learning about security content, but it does not push ongoing production detections into ES/SOAR.
  • C. Threat Hunting is a workflow and methodology within ES, not a content delivery app.
  • D. InfoSec is not a recognized Splunk product in this context - it's a general industry term, not an app.

Memory tip: Think of ESCU as a "subscription service" - the U stands for Update, reminding you it continuously updates your security content. If it has "Update" in the name, it's the one doing the delivering.

Topics

#ESCU#Enterprise Security#SOAR#security content delivery

Community Discussion

No community discussion yet for this question.

Full SPLK-5001 Practice