nerdexam
Splunk

SPLK-5002 · Question #67

When creating a case in Splunk SOAR, which action should be taken to correlate various findings (risk notables) to ensure all are actioned?

The correct answer is D. Search Splunk Enterprise Security for all related events based on key fields in a risk notable and. When creating a case in Splunk SOAR, correlation is achieved by searching Splunk Enterprise Security for all related events based on key fields in a risk notable, then deciding how to process and merge those events into the investigation. This ensures that all relevant risk…

Security Automation and Orchestration

Question

When creating a case in Splunk SOAR, which action should be taken to correlate various findings (risk notables) to ensure all are actioned?

Options

  • ASearch Splunk Enterprise Security for similar or duplicate events based on the threat_object field
  • BSearch Splunk Enterprise Security for all related events based on key fields in a notable and
  • CSearch Splunk Enterprise Security for similar or duplicate events based on the risk_object field in
  • DSearch Splunk Enterprise Security for all related events based on key fields in a risk notable and

How the community answered

(38 responses)
  • A
    3% (1)
  • B
    13% (5)
  • C
    5% (2)
  • D
    79% (30)

Explanation

When creating a case in Splunk SOAR, correlation is achieved by searching Splunk Enterprise Security for all related events based on key fields in a risk notable, then deciding how to process and merge those events into the investigation. This ensures that all relevant risk notables are actioned together for a complete response.

Topics

#SOAR case management#risk notables#event correlation#investigation workflow

Community Discussion

No community discussion yet for this question.

Full SPLK-5002 Practice