nerdexam
Splunk

SPLK-5002 · Question #18

What framework in Enterprise Security allows engineers to build detections using known malicious IOCs comparing them to event logs to find suspicious behavior?

The correct answer is C. Threat Intelligence Framework. The Threat Intelligence Framework in Splunk Enterprise Security enables engineers to build detections using known malicious IOCs (such as IPs, domains, or file hashes) and compare them against event logs. This framework automates IOC correlation to identify suspicious behavior.

Threat Intelligence Integration

Question

What framework in Enterprise Security allows engineers to build detections using known malicious IOCs comparing them to event logs to find suspicious behavior?

Options

  • AIncident Management Framework
  • BAsset & Intelligence Framework
  • CThreat Intelligence Framework
  • DOSINT Framework

How the community answered

(26 responses)
  • A
    4% (1)
  • B
    4% (1)
  • C
    81% (21)
  • D
    12% (3)

Explanation

The Threat Intelligence Framework in Splunk Enterprise Security enables engineers to build detections using known malicious IOCs (such as IPs, domains, or file hashes) and compare them against event logs. This framework automates IOC correlation to identify suspicious behavior.

Topics

#Threat Intelligence Framework#IOC matching#Enterprise Security#detection framework

Community Discussion

No community discussion yet for this question.

Full SPLK-5002 Practice