nerdexam
Splunk

SPLK-5002 · Question #1

Which Splunk Enterprise Security add-on facilitates the ingestion of Threat Intelligence data?

The correct answer is D. SA-ThreatIntelligence. The SA-ThreatIntelligence add-on in Splunk Enterprise Security is responsible for ingesting and normalizing threat intelligence data. It manages threat feeds and ensures they are available for correlation searches and risk analysis within ES.

Splunk Basics

Question

Which Splunk Enterprise Security add-on facilitates the ingestion of Threat Intelligence data?

Options

  • ATA-ThreatIntel
  • BSA-ESSIntel
  • CESS-Intel
  • DSA-ThreatIntelligence

How the community answered

(28 responses)
  • A
    4% (1)
  • B
    7% (2)
  • C
    14% (4)
  • D
    75% (21)

Explanation

The SA-ThreatIntelligence add-on in Splunk Enterprise Security is responsible for ingesting and normalizing threat intelligence data. It manages threat feeds and ensures they are available for correlation searches and risk analysis within ES.

Topics

#Enterprise Security#Threat Intelligence#add-on#SA-ThreatIntelligence

Community Discussion

No community discussion yet for this question.

Full SPLK-5002 Practice