nerdexam
Splunk

SPLK-5002 · Question #12

A detection engineer is using a threat defense informed strategy to define use cases. Which Splunk app would best facilitate their use case development process by cross referencing detections with…

The correct answer is B. Splunk Security Essentials App. The Splunk Security Essentials App is the best tool for developing use cases with a threat defense informed strategy. It allows engineers to cross-reference detections with the MITRE ATT&CK® Framework, providing guided analytic stories and mapping detections to adversary…

Threat Intelligence Integration

Question

A detection engineer is using a threat defense informed strategy to define use cases. Which Splunk app would best facilitate their use case development process by cross referencing detections with the MITRE ATT&CK® Framework?

Options

  • ASupporting add-on for MITRE ATT&CK®
  • BSplunk Security Essentials App
  • CEnterprise Security
  • DEnterprise Security Content Update App

How the community answered

(26 responses)
  • A
    8% (2)
  • B
    77% (20)
  • C
    12% (3)
  • D
    4% (1)

Explanation

The Splunk Security Essentials App is the best tool for developing use cases with a threat defense informed strategy. It allows engineers to cross-reference detections with the MITRE ATT&CK® Framework, providing guided analytic stories and mapping detections to adversary tactics and techniques.

Topics

#MITRE ATT&CK#Splunk Security Essentials#use case development#threat defense strategy

Community Discussion

No community discussion yet for this question.

Full SPLK-5002 Practice