SPLK-5002 · Question #67
When creating a case in Splunk SOAR, which action should be taken to correlate various findings (risk notables) to ensure all are actioned?
The correct answer is D. Search Splunk Enterprise Security for all related events based on key fields in a risk notable and. When creating a case in Splunk SOAR, correlation is achieved by searching Splunk Enterprise Security for all related events based on key fields in a risk notable, then deciding how to process and merge those events into the investigation. This ensures that all relevant risk…
Question
When creating a case in Splunk SOAR, which action should be taken to correlate various findings (risk notables) to ensure all are actioned?
Options
- ASearch Splunk Enterprise Security for similar or duplicate events based on the threat_object field
- BSearch Splunk Enterprise Security for all related events based on key fields in a notable and
- CSearch Splunk Enterprise Security for similar or duplicate events based on the risk_object field in
- DSearch Splunk Enterprise Security for all related events based on key fields in a risk notable and
How the community answered
(38 responses)- A3% (1)
- B13% (5)
- C5% (2)
- D79% (30)
Explanation
When creating a case in Splunk SOAR, correlation is achieved by searching Splunk Enterprise Security for all related events based on key fields in a risk notable, then deciding how to process and merge those events into the investigation. This ensures that all relevant risk notables are actioned together for a complete response.
Topics
Community Discussion
No community discussion yet for this question.