Pre-Winter Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Splunk Certified Cybersecurity Defense Engineer SPLK-5002 Question # 27 Topic 3 Discussion

Splunk Certified Cybersecurity Defense Engineer SPLK-5002 Question # 27 Topic 3 Discussion

SPLK-5002 Exam Topic 3 Question 27 Discussion:
Question #: 27
Topic #: 3

A SOC ' s Incident Response Standard Operating Procedure (SOP) calls for any phishing emails containing files to be detonated in Splunk Attack Analyzer for evaluation. Which of the following can an engineer implement to gain efficiency through automation?


A.

Automatically assign phishing-tagged findings to analysts to begin manual collection.


B.

Automatically send an email notification for all findings containing the phishing tag.


C.

Use a SOAR playbook to handle the Splunk Attack Analyzer submission and data-collection steps and make the information available to an assigned analyst.


D.

Use a SOAR playbook to submit the email to PhishTank and have it perform the Splunk Attack Analyzer submission.


Get Premium SPLK-5002 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.