SPLK-5002 · Question #93
A new playbook needs to be developed for automated phishing analysis and response. Configured in SOAR are integrations with Splunk Enterprise Security and actions from assets that pull in…
The correct answer is A. 1. Ingest the email from the mail vendor. The best workflow for automated phishing analysis and response is: 1. Ingest the email from the mail vendor - acquire the reported email for analysis. 2. Detonate the email in the automated threat analysis system and collect verdict - determine if the email is malicious and…
Question
A new playbook needs to be developed for automated phishing analysis and response. Configured in SOAR are integrations with Splunk Enterprise Security and actions from assets that pull in user-reported emails, perform automated threat analysis, add blocks on the proxy, and an EDR vendor to take various actions. Which would be the best workflow for the new playbook?
Options
- A
- Ingest the email from the mail vendor
- B
- Submit the user reported email from Splunk Enterprise Security
- C
- Submit the email from Splunk Enterprise Security
- D
- Ingest the email from the mail vendor
How the community answered
(24 responses)- A79% (19)
- B4% (1)
- C13% (3)
- D4% (1)
Explanation
The best workflow for automated phishing analysis and response is: 1. Ingest the email from the mail vendor - acquire the reported email for analysis. 2. Detonate the email in the automated threat analysis system and collect verdict - determine if the email is malicious and extract indicators. 3. Search the mail system for all users that received the email - identify impacted users. 4. Block any malicious URLs and processes with the proxy and EDR solutions - take targeted remediation based on verified malicious indicators.
Topics
Community Discussion
No community discussion yet for this question.