nerdexam
Splunk

SPLK-5002 · Question #16

A SOC's Incident Response Standard Operating Procedure (SOP) calls for any phishing emails containing files to be detonated in Splunk Attack Analyzer for evaluation. Which of the following can an…

The correct answer is D. Use a SOAR playbook to handle the Splunk Attack Analyzer submission and data collection. The most efficient approach is to use a SOAR playbook to automatically handle the Splunk Attack Analyzer submission and data collection steps, then present the results to the assigned analyst. This reduces manual effort, accelerates phishing investigation workflows, and aligns…

Security Automation and Orchestration

Question

A SOC's Incident Response Standard Operating Procedure (SOP) calls for any phishing emails containing files to be detonated in Splunk Attack Analyzer for evaluation. Which of the following can an engineer implement to gain efficiency through automation?

Options

  • AAutomatically send all findings containing the tag "phishing" to create an email notification for the
  • BUse a SOAR playbook to submit the email to PhishTank, which will automatically handle the
  • CAutomatically assign findings containing the tag "phishing" to analysts to speed up the start of
  • DUse a SOAR playbook to handle the Splunk Attack Analyzer submission and data collection

How the community answered

(47 responses)
  • A
    4% (2)
  • B
    2% (1)
  • C
    11% (5)
  • D
    83% (39)

Explanation

The most efficient approach is to use a SOAR playbook to automatically handle the Splunk Attack Analyzer submission and data collection steps, then present the results to the assigned analyst. This reduces manual effort, accelerates phishing investigation workflows, and aligns directly with

Topics

#SOAR playbook#phishing automation#Splunk Attack Analyzer#incident response SOP

Community Discussion

No community discussion yet for this question.

Full SPLK-5002 Practice