A correlation search must have the appropriate Adaptive Response Action configured when its intended outcome is creation of a notable event. Consequently, option C is correct.
The correlation search itself defines the analytics used to identify suspicious activity. Running that search successfully does not, by itself, mean every result automatically becomes a notable. The response configuration determines what Enterprise Security should do after the detection conditions are satisfied. Configuring the notable-related adaptive response action supplies that operational behavior.
This separation is important because the same detection framework can support different outcomes. Depending on design requirements, a correlation search may create analyst-facing findings, generate risk, invoke another response mechanism, or participate in additional automated workflows. The detection logic and response behavior therefore represent distinct parts of the engineering process.
A SOAR playbook is not a prerequisite for generating a notable; SOAR normally operates as a subsequent orchestration or response capability. Likewise, appending a | notable command to the SPL is not the configuration requirement being tested by this question.
Study Guide topics: Enterprise Security correlation searches, notable generation, Adaptive Response Actions, detection outcomes, response configuration.
Submit