Which of the following should an engineer do as they evaluate their Threat Detection and Incident Response lifecycle?
Which Splunk Enterprise Security add-on facilitates the ingestion of Threat Intelligence data?
Which of the following should be the primary reference when designing a new playbook in Splunk SOAR?
An engineer creates a new event type. What defines the association of this event type to an applicable data model?
An engineer notices that a detection is creating multiple Findings (notables) for the same potential incident. Which setting can be adjusted to reduce the number of generated findings (notables)?
When building detections using the Authentication Data Model, which values are recommended for use against the action field?
A Detection Engineer works closely with SOC leads to define expected analyst workflow, often documented as a Standard Operating Procedure (SOP). Which capability can be used to document expected analyst actions in an investigation?
Risk scores are associated with how many levels of risk in Enterprise Security by default?
In order to perform a complete data assessment, an engineer ' s role within Splunk must have which of the following?
The threat-hunting team has identified suspicious activity. An analyst manually creates a notable event using an event action to track the activity. How should a detection engineer ensure this activity automatically produces findings in the future?