nerdexam
Splunk

SPLK-5002 · Question #58

An EDR tool was recently purchased and needs to be integrated into existing Splunk SOAR playbooks. Which actions are typically associated with this type of asset?

The correct answer is C. Block hash, block process, quarantine device, get indicator. EDR platforms commonly support host-level actions such as blocking malicious hashes, stopping or blocking processes, quarantining infected endpoints, and retrieving indicators for investigation.

Security Automation and Orchestration

Question

An EDR tool was recently purchased and needs to be integrated into existing Splunk SOAR playbooks. Which actions are typically associated with this type of asset?

Options

  • ABlock device, remove email, detonate URL, get indicator
  • BBlock URL, block subdomain, quarantine device, get indicator, detonate URL
  • CBlock hash, block process, quarantine device, get indicator
  • DBlock hash, reset user password, quarantine device, get indicator

How the community answered

(37 responses)
  • A
    3% (1)
  • B
    5% (2)
  • C
    84% (31)
  • D
    8% (3)

Explanation

EDR platforms commonly support host-level actions such as blocking malicious hashes, stopping or blocking processes, quarantining infected endpoints, and retrieving indicators for investigation.

Topics

#EDR integration#SOAR asset actions#endpoint security#playbook actions

Community Discussion

No community discussion yet for this question.

Full SPLK-5002 Practice