nerdexam
Splunk

SPLK-5002 · Question #66

Which of the following is a reason to utilize ES risk framework as a part of detection building?

The correct answer is D. Help prioritize security findings based on their potential business impact. The ES (Enterprise Security) risk framework is designed to assign risk scores to events and entities, allowing security teams to prioritize security findings based on potential business impact. This ensures that the most critical risks are addressed first, improving overall…

Advanced Threat Hunting and Analytics

Question

Which of the following is a reason to utilize ES risk framework as a part of detection building?

Options

  • ACreate a feedback loop into threat intelligence to identify potential insider threats.
  • BHelp accelerate the run time of detections, allowing a faster mean time to detection.
  • CSimplify SOAR automation and remediation, lowering the mean time to recover.
  • DHelp prioritize security findings based on their potential business impact.

How the community answered

(27 responses)
  • A
    4% (1)
  • B
    7% (2)
  • C
    4% (1)
  • D
    85% (23)

Explanation

The ES (Enterprise Security) risk framework is designed to assign risk scores to events and entities, allowing security teams to prioritize security findings based on potential business impact. This ensures that the most critical risks are addressed first, improving overall response

Topics

#risk framework#detection building#risk-based alerting#business impact prioritization

Community Discussion

No community discussion yet for this question.

Full SPLK-5002 Practice