nerdexam
Splunk

SPLK-5001 · Question #95

An analyst needs to send notification emails after investigating a particular type of finding. Which feature should they ask an engineer to enable that will allow them to do so directly from Splunk…

The correct answer is B. Adaptive Response Action. By enabling an Adaptive Response Action for email in Splunk ES, analysts can trigger and send notification emails directly from the Incident Review workflow once they’ve investigated a notable

Incident Investigation and Response

Question

An analyst needs to send notification emails after investigating a particular type of finding. Which feature should they ask an engineer to enable that will allow them to do so directly from Splunk ES?

Options

  • ASplunk add-on for Email
  • BAdaptive Response Action
  • CEmail plug-in
  • DInclude in Next Steps

How the community answered

(37 responses)
  • A
    8% (3)
  • B
    86% (32)
  • C
    3% (1)
  • D
    3% (1)

Explanation

By enabling an Adaptive Response Action for email in Splunk ES, analysts can trigger and send notification emails directly from the Incident Review workflow once they’ve investigated a notable

Topics

#Adaptive Response#alert actions#Splunk ES#notification

Community Discussion

No community discussion yet for this question.

Full SPLK-5001 Practice