Pre-Winter Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Splunk Certified Cybersecurity Defense Engineer SPLK-5002 Question # 2 Topic 1 Discussion

Splunk Certified Cybersecurity Defense Engineer SPLK-5002 Question # 2 Topic 1 Discussion

SPLK-5002 Exam Topic 1 Question 2 Discussion:
Question #: 2
Topic #: 1

A new playbook needs to be developed for automated phishing analysis and response. Configured in SOAR are integrations with Splunk Enterprise Security and actions from assets that pull in user-reported emails, perform automated threat analysis, add blocks on the proxy, and an EDR vendor to take various actions. Which would be the best workflow for the new playbook?


A.

Ingest the email from the mail vendor

Detonate email in the automated threat analysis system and collect verdict, looking for malicious indicators

Search the mail system for all users that received the email

Block any malicious URLs and processes with the proxy and EDR solutions


B.

Submit the user reported email from Splunk Enterprise Security

Search the mail system for all users that received the email

Review results from the automated threat analysis

Block any malicious URLs and processes with the proxy and EDR solutions


C.

Submit the email from Splunk Enterprise Security

Search the mail system for all users that received the email

Review results from the automated threat analysis

Block any malicious URLs and processes with the proxy and EDR solutions


D.

Ingest the email from the mail vendor

Detonate email in the automated threat analysis system and collect verdict, looking for malicious indicators

Search the mail system for all users that received the email

Block all URLs and processes with the proxy and EDR solutions


Get Premium SPLK-5002 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.