SPLK-5002 · Question #28
Which of the following should an engineer do as they evaluate their Threat Detection and Incident Response lifecycle?
The correct answer is A. Evaluate the threat process lifecycle based on contextual business and industry knowledge. An engineer should evaluate the threat process lifecycle based on contextual business and industry knowledge. This ensures that detection and response efforts are aligned with the threats most relevant to the organization's environment, industry risks, and business priorities.
Question
Which of the following should an engineer do as they evaluate their Threat Detection and Incident Response lifecycle?
Options
- AEvaluate the threat process lifecycle based on contextual business and industry knowledge.
- BUse the MITRE ATT&CK® framework to evaluate the organization's risk appetite.
- CFocus efforts on the least impactful threat vectors.
- DEvaluate the threat process lifecycle based on profit margins and MTTR.
How the community answered
(24 responses)- A79% (19)
- B4% (1)
- C4% (1)
- D13% (3)
Explanation
An engineer should evaluate the threat process lifecycle based on contextual business and industry knowledge. This ensures that detection and response efforts are aligned with the threats most relevant to the organization's environment, industry risks, and business priorities.
Topics
Community Discussion
No community discussion yet for this question.