nerdexam
Splunk

SPLK-5002 · Question #62

Engineers are commonly asked to turn data sources like EDR alerts into risk events. Doing so requires a dynamic mapping of the signatures in the rule to MITRE ATT&CK®. Which of the following fields…

The correct answer is D. annotations.mitre_attack.mitre_technique_id. Risk-based alerting expects MITRE ATT&CK® mappings to be provided through the annotations namespace. The correct dynamic field for specifying the ATT&CK technique ID is annotations.mitre_attack.mitre_technique_id, which Splunk uses when generating risk events.

Threat Intelligence Integration

Question

Engineers are commonly asked to turn data sources like EDR alerts into risk events. Doing so requires a dynamic mapping of the signatures in the rule to MITRE ATT&CK®. Which of the following fields could be used to dynamically set the MITRE ATT&CK® technique ID for the EDR alerts?

Options

  • Amitre_attack.tactic_id
  • Bannotations.mitre_attack.tactic_id
  • Cmitre_attack.mitre_technique_id
  • Dannotations.mitre_attack.mitre_technique_id

How the community answered

(36 responses)
  • A
    3% (1)
  • B
    8% (3)
  • C
    6% (2)
  • D
    83% (30)

Explanation

Risk-based alerting expects MITRE ATT&CK® mappings to be provided through the annotations namespace. The correct dynamic field for specifying the ATT&CK technique ID is annotations.mitre_attack.mitre_technique_id, which Splunk uses when generating risk events.

Topics

#MITRE ATT&CK mapping#risk events#EDR annotations#annotations field

Community Discussion

No community discussion yet for this question.

Full SPLK-5002 Practice