nerdexam
Splunk

SPLK-5002 · Question #96

While working with the SOC analysts to review current contextualization processes, a request for automation has been raised by the SOC team. They are asking for a new automation that will check a…

The correct answer is B. Adaptive Response Action or Input Playbook. The SOC can implement this automation using either an Adaptive Response Action (triggered from a notable or event) or an Input Playbook (triggered when a URL is submitted for analysis). Both approaches allow automated checks against a remote URL filtering list to enrich and…

Security Automation and Orchestration

Question

While working with the SOC analysts to review current contextualization processes, a request for automation has been raised by the SOC team. They are asking for a new automation that will check a potentially malicious URL against a remote URL filtering list. Which of the following options will work for them?

Options

  • ANeither Adaptive Action or Input Playbook
  • BAdaptive Response Action or Input Playbook
  • CAdaptive Response Action
  • DInput Playbook

How the community answered

(40 responses)
  • A
    15% (6)
  • B
    75% (30)
  • C
    8% (3)
  • D
    3% (1)

Explanation

The SOC can implement this automation using either an Adaptive Response Action (triggered from a notable or event) or an Input Playbook (triggered when a URL is submitted for analysis). Both approaches allow automated checks against a remote URL filtering list to enrich and contextualize findings.

Topics

#adaptive response actions#input playbooks#URL filtering#SOAR

Community Discussion

No community discussion yet for this question.

Full SPLK-5002 Practice