nerdexam
Splunk

SPLK-5002 · Question #31

The SOC Manager requested a better method to standardize the list of tasks that analysts follow when they evaluate events or cases. Which Splunk SOAR feature allows the creation of SOPs based on…

The correct answer is A. Workbooks. Workbooks in Splunk SOAR allow SOC managers to standardize analyst workflows by defining SOPs (Standard Operating Procedures) as structured task lists. These can be applied automatically based on event type or attack vector, ensuring consistency in investigations.

Security Automation and Orchestration

Question

The SOC Manager requested a better method to standardize the list of tasks that analysts follow when they evaluate events or cases. Which Splunk SOAR feature allows the creation of SOPs based on criteria like the type of event or attack vector?

Options

  • AWorkbooks
  • BEvents
  • CCases
  • DIncidents

How the community answered

(58 responses)
  • A
    76% (44)
  • B
    7% (4)
  • C
    3% (2)
  • D
    14% (8)

Explanation

Workbooks in Splunk SOAR allow SOC managers to standardize analyst workflows by defining SOPs (Standard Operating Procedures) as structured task lists. These can be applied automatically based on event type or attack vector, ensuring consistency in investigations.

Topics

#SOAR workbooks#SOP standardization#analyst workflow#incident response

Community Discussion

No community discussion yet for this question.

Full SPLK-5002 Practice