Splunk
SPLK-5002 · Question #58
An EDR tool was recently purchased and needs to be integrated into existing Splunk SOAR playbooks. Which actions are typically associated with this type of asset?
The correct answer is C. Block hash, block process, quarantine device, get indicator. EDR platforms commonly support host-level actions such as blocking malicious hashes, stopping or blocking processes, quarantining infected endpoints, and retrieving indicators for investigation.
Security Automation and Orchestration
Question
An EDR tool was recently purchased and needs to be integrated into existing Splunk SOAR playbooks. Which actions are typically associated with this type of asset?
Options
- ABlock device, remove email, detonate URL, get indicator
- BBlock URL, block subdomain, quarantine device, get indicator, detonate URL
- CBlock hash, block process, quarantine device, get indicator
- DBlock hash, reset user password, quarantine device, get indicator
How the community answered
(37 responses)- A3% (1)
- B5% (2)
- C84% (31)
- D8% (3)
Explanation
EDR platforms commonly support host-level actions such as blocking malicious hashes, stopping or blocking processes, quarantining infected endpoints, and retrieving indicators for investigation.
Topics
#EDR integration#SOAR asset actions#endpoint security#playbook actions
Community Discussion
No community discussion yet for this question.